Opened 3 years ago

Closed 3 years ago

#22932 closed enhancement (fixed)

Support an amnesiac profile directory.

Reported by: yawning Owned by: yawning
Priority: Medium Milestone:
Component: Archived/Tor Browser Sandbox Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Basic idea is to copy the profile directory into a new tmpfs mount inside the container on each launch so that even if firefox writes evil to it, said evil will be non-persistent.

The drawback is that this applies to bookmarks and preferences, so it can't be the default behavior, but as an "improve security" option, it's easy to do.

Child Tickets

Change History (4)

comment:1 Changed 3 years ago by yawning

Status: newaccepted
Summary: Support a non-volatile profile directory.Support an amnesiac profile directory.

Change the summary to more accurately reflect how this works.

comment:3 Changed 3 years ago by Dbryrtfbcbhgf

Resolution: fixed
Status: closedreopened

Should it also copy the "Caches" directory into a new tmpfs mount inside the container?

comment:4 Changed 3 years ago by yawning

Resolution: fixed
Status: reopenedclosed

At least pretend to understand the existing behavior, and don't reopen tickets.

Note: See TracTickets for help on using tickets.