Author Topic: Google Chrome Linux Sandboxing  (Read 1506 times)

Offline cirrus_minor

  • Full Member
  • ***
  • Posts: 123
  • ☆★ #watp ★☆
    • cirrus minor
Google Chrome Linux Sandboxing
« on: May 05, 2012, 10:20:24 AM »
This Is For Linux Only

Download the latest chrome browser with new V8 engine here    (64 bit link)

I tried this and i was truly blown away by the speed so it seems the V8 engine is very aptly named indeed ,see here,   im going to show you how to sandbox chrome or chromium browsers for those of us who are security concious.  You can learn more about the benefits here

Type into your Google Chrome or Chromium browser:
about:sandbox

Mine shows seccomp sandbox is enabled
1) Make a shortcut to the browser and in the properties edit command line to read:

google-chrome --enable-seccomp-sandbox %U

in chromium it should look similar to this

/usr/bin/chromium-browser --enable-seccomp-sandbox %U

in google chrome should be similar to this

/opt/google/chrome/google-chrome --enable-seccomp-sandbox %U

2) X out of current browser session and start another using newly created shortcut

3) Again type in about:sandbox to url bar to verify that you are now sandboxed

Another cool tip i found for  all operating systems using chrome  is if you type chrome://flags into url bar you get options to tweak some hidden settings.

I hope you found this beneficial.

cirrus
« Last Edit: May 05, 2012, 10:35:37 AM by cirrus_minor »


$ PCLOS~KDE~ 2011.Kernel:2.6.38.8
CPU:Intel® Pentium D 2x3.GHz
GPU:ASUS® [G92 EN8800 GT TOP] 512MB DDR3.
Memory:3072MB'DDR2 | HDD Size 1TB
Audio:Audigy2 ZS 7.1

Offline Just17

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 11058
  • MLUs Forever!
Re: Google Chrome Linux Sandboxing
« Reply #1 on: May 05, 2012, 10:48:16 AM »
Thanks for the hints.

Does the use of  seccomp  interfere with on line activities in obvious ways?

Only wondering what to expect from its use.

I had not been aware of this or indeed the about:flags page.

Thanks for posting. ;)
MLUs rule the roost!

Linux XPS 3.4.48-pclos1.bfs  64 bit
Intel Core2 Quad CPU Q9450 @ 2.66GHz
4 GB RAM
MCP51 High Def Audio
GeForce GTX 550 Ti
PHILIPS  ‎DVD+-RW DVD8701
‎Logitech ‎BT Mini-Receiver
Afatech DTT

Offline cirrus_minor

  • Full Member
  • ***
  • Posts: 123
  • ☆★ #watp ★☆
    • cirrus minor
Re: Google Chrome Linux Sandboxing
« Reply #2 on: May 05, 2012, 11:52:29 AM »
I havent noticed nothing untoward , check out http://code.google.com/p/seccompsandbox/wiki/overview   for more info.


$ PCLOS~KDE~ 2011.Kernel:2.6.38.8
CPU:Intel® Pentium D 2x3.GHz
GPU:ASUS® [G92 EN8800 GT TOP] 512MB DDR3.
Memory:3072MB'DDR2 | HDD Size 1TB
Audio:Audigy2 ZS 7.1

Offline Just17

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 11058
  • MLUs Forever!
Re: Google Chrome Linux Sandboxing
« Reply #3 on: May 05, 2012, 12:21:58 PM »
I havent noticed nothing untoward , check out http://code.google.com/p/seccompsandbox/wiki/overview   for more info.


Thanks ... I had read that .....  but your comment is more valuable to me  :D

If you have not noticed anything then it might be OK to use full time ......  I will set it and see what happens.

Thanks.  ;)
MLUs rule the roost!

Linux XPS 3.4.48-pclos1.bfs  64 bit
Intel Core2 Quad CPU Q9450 @ 2.66GHz
4 GB RAM
MCP51 High Def Audio
GeForce GTX 550 Ti
PHILIPS  ‎DVD+-RW DVD8701
‎Logitech ‎BT Mini-Receiver
Afatech DTT

Offline YouCanToo

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 5383
  • Location: Lebanon, OR., USA
    • Spreading the word.......
Re: Google Chrome Linux Sandboxing
« Reply #4 on: May 05, 2012, 12:22:54 PM »
This Is For Linux Only

Download the latest chrome browser with new V8 engine here    (64 bit link)

I tried this and i was truly blown away by the speed so it seems the V8 engine is very aptly named indeed ,see here,   im going to show you how to sandbox chrome or chromium browsers for those of us who are security concious.  You can learn more about the benefits here

Type into your Google Chrome or Chromium browser:
about:sandbox

Mine shows seccomp sandbox is enabled
1) Make a shortcut to the browser and in the properties edit command line to read:

google-chrome --enable-seccomp-sandbox %U

in chromium it should look similar to this

/usr/bin/chromium-browser --enable-seccomp-sandbox %U

in google chrome should be similar to this

/opt/google/chrome/google-chrome --enable-seccomp-sandbox %U

2) X out of current browser session and start another using newly created shortcut

3) Again type in about:sandbox to url bar to verify that you are now sandboxed

Another cool tip i found for  all operating systems using chrome  is if you type chrome://flags into url bar you get options to tweak some hidden settings.

I hope you found this beneficial.

cirrus


How about adding this as a how-to in the knowledgebase. http://pclinuxoshelp.com/index.php/Category:HowTo   It would make a great addition.




Be sure to visit the NEW Knowledge Base


Linux is user-friendly- it's just picky who its friends are!

Offline cirrus_minor

  • Full Member
  • ***
  • Posts: 123
  • ☆★ #watp ★☆
    • cirrus minor
Re: Google Chrome Linux Sandboxing
« Reply #5 on: May 05, 2012, 01:28:58 PM »
Feel free to add it , if i remember right i had issues making account over there (prolly my noobness & no fault of your own)  :)


$ PCLOS~KDE~ 2011.Kernel:2.6.38.8
CPU:Intel® Pentium D 2x3.GHz
GPU:ASUS® [G92 EN8800 GT TOP] 512MB DDR3.
Memory:3072MB'DDR2 | HDD Size 1TB
Audio:Audigy2 ZS 7.1

Offline Archie

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 8821
  • Aurum nostrum non est aurum vulgi.
Re: Google Chrome Linux Sandboxing
« Reply #6 on: May 05, 2012, 10:04:15 PM »
Thanks for the great tip, cirrus_minor. :D
Since 2006 | LiCo 401868 | Bare Metal | What is necessary is never unwise. --Sarek, 2258.42


Offline cirrus_minor

  • Full Member
  • ***
  • Posts: 123
  • ☆★ #watp ★☆
    • cirrus minor
Re: Google Chrome Linux Sandboxing
« Reply #7 on: May 07, 2012, 12:39:04 PM »
Thanks for the great tip, cirrus_minor. :D

You are very welcome archie , u guys have welcomed me & taught me so much through these forums & via IRC support channel during the past my 8 months of my linux usage and have made the transition all the more sweeter for me , god willing i will be taught much more in the coming years ,   it feels good to give a tiny bit back to you guys.
   regards
    cirrus


$ PCLOS~KDE~ 2011.Kernel:2.6.38.8
CPU:Intel® Pentium D 2x3.GHz
GPU:ASUS® [G92 EN8800 GT TOP] 512MB DDR3.
Memory:3072MB'DDR2 | HDD Size 1TB
Audio:Audigy2 ZS 7.1

Offline Just17

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 11058
  • MLUs Forever!
Re: Google Chrome Linux Sandboxing
« Reply #8 on: May 07, 2012, 01:00:17 PM »
Only to report that I have been using Chromium fully sandboxed since my last post, and have not met with any difficulties.  :D

Thanks again cirrus_minor  ;)
MLUs rule the roost!

Linux XPS 3.4.48-pclos1.bfs  64 bit
Intel Core2 Quad CPU Q9450 @ 2.66GHz
4 GB RAM
MCP51 High Def Audio
GeForce GTX 550 Ti
PHILIPS  ‎DVD+-RW DVD8701
‎Logitech ‎BT Mini-Receiver
Afatech DTT

Offline mag

  • Full Member
  • ***
  • Posts: 68
Re: Google Chrome Linux Sandboxing
« Reply #9 on: May 08, 2012, 03:04:21 AM »
Thanks for the Tip. Working fine here so far.

Words worth spreading!

Offline menotu

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 15515
  • ┌∩┐(◕_◕)┌∩┐
PCLinuxOS 32bit KDE 4.10.4; kernel-3.4.11-pclos1.bfs & 64bit 3.4.38bfs; NVidia GeForce 8400GS 1GB 310.19 driver

Sony Vaio SVE1513A4ESI Laptop, Intel Core i5, 2.6GHz, 6GB RAM, 750GB, 15.6" Intel HD Graphics 4000

Offline longtom

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 3339
  • Satellite Station Africa
Regards longtom

PCLinuxOS KDE 32bit
Intel Core 2 Duo E2200 / 2.2 GHz
2GB Ram
Nvidia GT610