Re: Firefox Security Newsletter - Q2 2017

Alex Gaynor <[email protected]> Tue, 8 Aug 2017 09:22:32 -0400
Newsgroups gmane.comp.mozilla.security
Message-ID <CAGzK4uPVMY=ihMwjkeq80pOXXJ12ZSNUKNnzmJDn_mjy-rFv-w@mail.gmail.com>
pledge is not in upstream-Chromium, it's a patch applied by OpenBSD.

Alex

On Tue, Aug 8, 2017 at 4:57 AM, Kevin Chadwick <[email protected]> wrote:

> Chrome doesn't support r^x on OpenBSD but Firefox does with it's more
> secure jit etc. However Chrome does have the nice and simple pledge
> sandboxing on OpenBSD but not sure if those pledge calls are upstreamed. I
> imagine if sandboxed for the other OS that Firefox is structured in such a
> way that pledge calls can be added easily. If that were true, Firefox on
> OpenBSD would become the only browser with enforced r^x without
> functionality breakage and sandboxing by default not to mention optional
> decent security plugins. Put that in your pipe and smoke it, those that
> excluded firefox from the google sec testing event due to a reported lack
> of security improvements. :D
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>