By default Chromium on OpenBSD (not so) recently got OpenBSD’s unveil(2) support. That means that of you run Chromium with
Is it so critical and is it necessary to make a container for the browser? Why does the operating system give such permissions by default?
--enable-unveil
flag then it will be prevented from accessing anything other than the ~/Downloads directory. No such thing on FreeBSD exists. Firefox or Chromium have access to all files user can read – even to your system sshd(8) keys or even worse to your private keys laying in the ~/.ssh dir.Is it so critical and is it necessary to make a container for the browser? Why does the operating system give such permissions by default?