you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 23 hours ago (5 children)

You’d still be fine if you’re not exposing public services or visiting actively-malicious websites.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 1 point 21 hours ago (4 children)

    You are underestimating things. Unmalicious websites can still host malicious content by users, for example.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 21 hours ago* (3 children)

    Okay, wanna give me a link to a PoC example you set up?

    I’ll reimage my laptop to an old Ubuntu ISO of your choice, and visit your link. Happy to be proven wrong.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 21 hours ago (2 children)

    No, I will not spend hours of my time to win an irrelevant internet argument. :P

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 21 hours ago* (1 child)

    Fair enough!

    But I can tell you as a cybersecurity expert that you’d have a hard time finding a way to get any sort of remote execution from user-generated content on any major site, much less an exploitable browser sandbox escape.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 59 minutes ago

    I think web browser exploits wouldn't be an issue on ubuntu anyways, as major web browsers do get regular upgrades there (or are not even installed via apt but snap nowadays). Also web browsers use sandboxes. I'm more worried about users downloading any kind of content and interacting with it via more niche software, like image viewers (though with glycin they nowadays also do sandboxing).

  • source
  • parent