Hacker News new | past | comments | ask | show | jobs | submit login

I no longer use Tor either (unless I have to for work projects such as remote pentesting).

What is you opinion of Landlock (Linux kernel 5.13 and newer)? If we wrap vanilla FireFox in LandLock, proxy that to tor and use Apparmor/Tomoyo to further limit what FireFox could do (when it gets compromised) then I think that would be a much safer approach than using the Tor Browser Bundle.

Here's a landlock wrapper (in Go) for FireFox: https://github.com/62726164/misc/blob/main/go/landlock/firef...

Also, I've only ever been able to get Tomoyo to work as MAC for FireFox. SELinux and Apparmor were too difficult.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: