←back to thread

357 points vxvrs | 1 comments | | HN request time: 0s | source
Show context
scrps ◴[] No.45949158[source]
Nonpersistent vm-based browser, I use qemu + cage + firefox and some glue logic to fire up a copy of a base image which gets deleted on exit. Fires up slower than a native firefox instance but runs all the same.

Can containerize for the less paranoid and less work but browsers touching host kernel gives me the ick as does the idea of trying to write ebpf policies for firefox to mitigate. Browsers are pain.

replies(2): >>45949204 #>>45950005 #
captainkrtek ◴[] No.45949204[source]
This sounds interesting, do you have this written up anywhere?
replies(1): >>45949939 #
1. scrps ◴[] No.45949939[source]
I sadly do not atm beyond some notes but I can if there is interest.