this post was submitted on 18 Mar 2024
75 points (100.0% liked)
Privacy
31982 readers
348 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
For a anonymous browser, but not for a secure browser. The paper is purely about privacy and anonymity. No security (sandboxing, mitigations) here.
Chromium sandboxing means nothing when it leaks so much data. Tor Project has fleshed that out pretty well.
The attacker can't gain access to the host with javascript.
A browser that support javascript but doesn't have sandboxing might not leak these data but when their are bug in their js implementation, the attacker can gain more access to the host.
Pretty sure that both Firefox and Chromium have sandboxing. What browser are you talking about? Also the only form of attack is not a direct browser script attack. It can also be used to extract metadata, which is used to attack someone in other ways or through other software or OS.
I think you need to learn to debate coherently on internet, and work on weird ideas you have formed in your head around security.
Threat model. Regular user aren't attacked this way?