Re: Firefox Security Newsletter - Q2 2017

Kevin Chadwick <[email protected]> Tue, 8 Aug 2017 09:57:00 +0100
Newsgroups gmane.comp.mozilla.security
Message-ID <CANNfpqdgEsiD89q5G3LKrj3zkkP_Pm_q_UnCjnqvwz8umsfxZQ@mail.gmail.com>
Chrome doesn't support r^x on OpenBSD but Firefox does with it's more
secure jit etc. However Chrome does have the nice and simple pledge
sandboxing on OpenBSD but not sure if those pledge calls are upstreamed. I
imagine if sandboxed for the other OS that Firefox is structured in such a
way that pledge calls can be added easily. If that were true, Firefox on
OpenBSD would become the only browser with enforced r^x without
functionality breakage and sandboxing by default not to mention optional
decent security plugins. Put that in your pipe and smoke it, those that
excluded firefox from the google sec testing event due to a reported lack
of security improvements. :D