Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

surely tor and the browser should be in separate dockers? #2

Open
williame opened this issue Oct 8, 2013 · 1 comment
Open

surely tor and the browser should be in separate dockers? #2

williame opened this issue Oct 8, 2013 · 1 comment

Comments

@williame
Copy link

williame commented Oct 8, 2013

The tor proxy should be run in docker.

This docker itself contains a separate browser docker embedded. This browser docker is firewalled so the only outbound connection it can make is to the tor proxy.

Then the browser can allow plugins etc; normally the tor browser bundle disabled plugins for fear they can avoid using the tor proxy, but in this case the firewalled docker would suddenly enable a real advantage over the normal tor browser.

And rather than naked x-forwarding, using vnc or similar bitmap-scraping based protocol may reduce the attack surface further?

@paulczar
Copy link
Owner

paulczar commented Oct 8, 2013

yeah, I went for ease to install ... rather than sensible :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants