Re: [Tails-dev] Firejail for unsafe browser and SSR screen r…

Delete this message

Reply to this message
Author: intrigeri
Date:  
To: jg30, tails-dev
Subject: Re: [Tails-dev] Firejail for unsafe browser and SSR screen recorder
Hi,

jg30--- via Tails-dev:
> So I had an idea that maybe we could incorporate the Firejail sandboxing
> program to the unsafe web browser.


When we switch to Wayland (#12213) we'll need to change the way we run
the Unsafe Browser. In particular, we won't be able to run it under
a dedicated user anymore. So indeed, we'll need to look for other
options that allow us to configure specific nameserver and firewall
rules for this app. I'd love to see a prototype that uses Firejail
or similar technologies to do this :)

One thing we want to fix at the same time: making the Unsafe Browser
accessible (#7502).

> I looked at the applications that Tails comes with and saw that there
> really was no screen recorder in there.


GNOME supports this natively:
https://wiki.gnome.org/Projects/GnomeShell/CheatSheet#Screencast_recording

Note that most other screen recording software are incompatible with
Wayland by design. I don't know what's the status of the Wayland APIs
and GNOME implementation to allow external screen recorders to request
permission from the user to record the screen.

Cheers,
--
intrigeri