http://secure45nbquibuw6thmenrfamhobdkkrllgxrtayn4sgmnexremexyd.onion/firefox-chromium.html
However, Firefox's seccomp filter
is substantially less restrictive than the one imposed by Chromium's sandbox and does not restrict anywhere near the same amount of syscalls and their arguments.
One example of this is that there is very little filtering of ioctl calls — only TTY-related ioctls
are blocked in the content process . This is problematic because ioctl is a particularly powerful syscall that presents a massive kernel attack surface...