View Single Post
wicket's Avatar
Posts: 634 | Thanked: 3,266 times | Joined on May 2010 @ Colombia
#31
Originally Posted by Maemish View Post
Have you something to say about the kiosk mode?
I haven't been able to find much information on kiosk mode but from what I can tell it is exactly that: a mode designed to run Chromium for public kiosks/terminals, normally intended to run a single website or web app. In other words, start the browser automatically, run full screen and hide all controls (buttons, menus, etc) from the user. Any additional security layers that it provides would be to protect from someone with physical access to the device and it makes little sense to use it for general web browsing on a device you own. There might be a slight memory advantage as it doesn't load user controls.

Originally Posted by Maemish View Post
Or what would be good parameters to start the firejail with?
For something like Chromium, I probably wouldn't bother using Firejail. The Chromium developers are very hot on security and it's already heavily sandboxed. They already do system call filtering with seccomp-bpf (if the kernel provides it) and I'm pretty sure they already drop unneeded capabilities. Don't forget that excessive sandboxing can break stuff. Google know their product better than the Firejail developer so I would just trust them on this one.
__________________
DebiaN900 - Native Debian on the N900. Deprecated in favour of Maemo Leste.

Maemo Leste for N950 and N9 (currently broken).
Devuan for N950 and N9.

Mobile devices with mainline Linux support - Help needed with documentation.

"Those who do not understand Unix are condemned to reinvent it, poorly." - Henry Spencer
 

The Following 2 Users Say Thank You to wicket For This Useful Post: