On Wed, Oct 03, 2007 at 01:12:46AM +0100, Alan Cox wrote:
well, being sick of the number of times one has to upgrade the browser
for exploits, I addressed it in a different way.
I ran firefox setuid to a different (not my main user), uid+gid, gave
my main account that gid as a supplemental group, and gave that uid
access to the X magic cookie.
... which only changes the nature of any exploit that might occur - any
injected code would have to go via X to attack my main account.
DF
-