Security advantage of private-tmp (in firefox.profile) #4108
-
The provided profile for Firefox includes I could not find a reason for the enabled However, I do not want to establish a setup with possible security concerns, thus the question: What was the reason to include Environment
Compile time support: |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
It's safe to
You will hardly never find a reason why restriction foo is in profile bar.
Replace tmp with D-Bus: Some programs may have sockets in
Access to |
Beta Was this translation helpful? Give feedback.
It's safe to
ignore private-tmp
if you usewhitelist /tmp/foo
:You will hardly never find a reason why restriction foo is in profile bar.
private-tmp
isolates/tmp
inside the sandbox from/tmp
of the system. And isolation between your system and the sandbox is that what you want if you use firejail.Replace tmp with D-Bus:
D-Bus is generally seen as…