Re: Firefox Security Newsletter - Q2 2017
Alex Gaynor <[email protected]> Tue, 8 Aug 2017 09:22:32 -0400
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAGzK4uPVMY=ihMwjkeq80pOXXJ12ZSNUKNnzmJDn_mjy-rFv-w@mail.gmail.com> |
pledge is not in upstream-Chromium, it's a patch applied by OpenBSD. Alex On Tue, Aug 8, 2017 at 4:57 AM, Kevin Chadwick <[email protected]> wrote: > Chrome doesn't support r^x on OpenBSD but Firefox does with it's more > secure jit etc. However Chrome does have the nice and simple pledge > sandboxing on OpenBSD but not sure if those pledge calls are upstreamed. I > imagine if sandboxed for the other OS that Firefox is structured in such a > way that pledge calls can be added easily. If that were true, Firefox on > OpenBSD would become the only browser with enforced r^x without > functionality breakage and sandboxing by default not to mention optional > decent security plugins. Put that in your pipe and smoke it, those that > excluded firefox from the google sec testing event due to a reported lack > of security improvements. :D > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security >