- Package:
- firefox-esr
- Source:
- firefox-esr
- Description:
- Mozilla Firefox web browser - Extended Support Release (ESR)
- Submitter:
- Antti-Pekka Johannes Känsälä
- Date:
- 2024-05-06 16:30:03 UTC
- Severity:
- normal
Dear Maintainer, please consider https://lists.debian.org/debian-user/2024/03/msg00721.html I am worried Gmail in a Firefox tab is able to break out of Firefox somehow, gaining unauthorized access to 128 files on a mounted USB stick. The desired behavior is that stick can be unmounted cleanly right after a single attached file is uploaded in Gmail. (In my test case an encrypted binary of no importance to the issue.) Clinging problem persists with full Debian reinstalls of recent stable minor versions.
Sorry for the amount of text that follows: MY MONOLOGUE ON FACEBOOK 30.-31.3.2024 Antti-Pekka Känsälä antti.pekka.kansala@iki.fi If it's not in Debian, but it's because of my activity, I'm somewhat out of ideas. Out of ideas concerning my own data security. In that case, I better move on, and focus on something else. (The problem has persisted for some time. I have quietly assumed my machine has been breached, by legal (not to say legitimate) means (in short, I've been under the "official eye"), that the Debian project has been forced to comply to, or by means that are beyond software. Thus my helplessness continues.) Frequent reinstallations of the system clearly won't help, I have tried that. Is it possible, that I have bogus installation media, and cryptographical verification fails in my case? Just my thoughts. I think this is the second time I'm in this kind of despair with Debian. However, I know of no other way to use a computer, that would come even close in quality for my needs. Thanks. The GNU/Linux Debian distribution of Linux is the basis for most other distributions. It affects the entire digital world, that it works correctly. Their security team I believe includes the best. I think they have a public disclosure policy, once they discover a problem. If there is a problem here, I may never even find out where it was, but it will be fixed, by the best. You should use Debian too. The USB stick problem is not the only symptom. The other is complete lockups, that may well be just because of old hardware. However, if the system is breached, the lockups could be intentional. The problem could be somewhere completely elsewhere from USB sticks, it's just that someone's playing interested in my sticks on a breached system. Haha... So it's ok, if it's just the corrupted officials monitoring me, so long as the problem is not in Debian, God forbid! It's quite the system. No systems limps on quite as well, even when completely breached... Things sure happen fast, when a computer most likely is breached. Nearly all of the attack tools targeted at my machine must be fully automated. Not much use being even the best sysadmin on a breached machine, it's people elsewhere who investigate. Why would Gmail running in Firefox be interested in 128 files on my USB stick, in addition to the 1 that I have just uploaded as an e-mail attachment? Good question. Because they are not, but running Gmail in Firefox reveals something about how the system is compromised. There was news just today, I think, of a major backdoor problem, that was discovered. They suspect it was definitely by a governmental level actor. What is happening on my machine could be a consequence of the backdoor problem, but I'm just one of the God knows how many affected, and my case may or may not be relevant at all to figuring out what else has become corrupted. What is worrisome however, is that this seems to be happening on several versions of recently, freshly-reinstalled Debian stable. I saw someone writing that "no version of Debian stable is known to be affected", but this could change. I got some very professional help, quickly, from the debian-user mailing list. Being worried about USB stick security must be well-known. I have been aware of the "lsof" command before, to display open files, and I think I may have even tried it to investigate this problem, but have given up, for the reason that there's not really anything I can do if my activity is just being "legally" monitored by officials. I'm really annoyed by what I gather, that the Debian project is legally obliged to allow such official monitoring. On the other hand, the situation is no different from phones, which the police (at least) can tap. My understanding is, that Debian is close to a system, that not even the authorities would be able to monitor, were it not for their "legal" intervention in the system's development. I do feel a bit digitally raped here. With Windows it would be constantly in bed with Bill Gates? With Apple... Well. You hear of Windows computers getting slow with age? Well, I got alarmed when on Linux an action started to take two seconds on this old machine! You just kind of have to settle with something, that you assume is a noticeable tap on your system, from month to month, by the officials, legally? The backdoor I mentioned has been fixed now, and possibly did not affect my suspected problem. I have some ideas though, why Gmail "might" be interested in USB sticks... Enough so to break out of Firefox? In that case, what I'm experiencing could just be a minor problem. Maybe just in Firefox, but is it really being exploited by our honest friend Google?! I have nowhere near complete evidence, under which conditions can the system try to steal files off my USB sticks. I just know I can't use USB sticks securely here. To some people, that might sound surprising, if you read what they say about malware, etc., and warn about unknown sticks. But with GNU/Linux Debian there have actually been standards of security, you could actually hope that USB sticks would work for their intended purpose! If Firefox has a hole, it's going to somewhat limit my browsing experience. Maybe as workaround, I will try switching to another browser at some point. Firefox just happens to ship as the default. A fancy file chooser dialogue, that stays around analyzing the directory is now suspected. But it could be that someone is interested in what kind of binaries people try to e-mail to somewhere from their USB sticks (!) (The backdoor discovery I mentioned yesterday is a nice example, of how things work in the open source community. The problem was admitted, discussed openly, and fixed the same day. Regarding Debian, it only affected developmental versions, not the stable distribution I'm using. I read some SSH tools were compromised, if they had been used by early-adopter developers throughout the world, a huge number of systems could still be corrupted all around the world. Even though the root of the problem was fixed in less than a day, after it was brilliantly discovered by noting that a particular infected program ran a bit slower, that it should have!) If you got interested in my suspected problem, the technical discussion is here: https://lists.debian.org/debian-user/2024/03/msg00721.html LISTS.DEBIAN.ORG Debian 12.5 up-to-date Xfce, Firefox clings to USB stick I'm not sure if I should even bother reporting this to Mozilla, since their page hardly even has a simple feature to report problems! To contribute to data security responsibly, I think I am going to need to push this all the way through, until I get an answer, or see the problem fixed. The problem could be local to Debian, so I think I'll "stick" to that for now. I just used the Debian "reportbug" tool for the first time in my life, on the package "firefox-esr". It would be a way to begin contributing, to report *everything* I notice. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068122 BUGS.DEBIAN.ORG bugs.debian.org bugs.debian.org Who knows, I may have "hit jackpot"! Now that I think of it, I'm no longer sure how I mounted the stick in the first place. Did I double click the icon, opening a window manager window, that promptly began analyzing the directory in the background? Is it just that? Previews of files were still being computed when I was already done with Gmail, and tried to unmount? No... I think this is related to someone being interested in me apparently planning on using Gmail to send encrypted data. They may have a right to be interested. But not by compromising my Debian! I don't always see this kind of behavior, with the same stick, even if I quickly plug it in to retrieve a single file. I don't know where the previews are stored, not on the stick, I think. I mean, it took a minute or so, before unmounting cleanly, and 129 files on the stick really were open by the browser. If I copy a single file out of a stick, and it is done, then the expected behavior is that the stick can be unmounted. If it's a storage device, not an espionage device. And, I've noticed manual mounting in the terminal, copying the file to disk, then unmounting in the terminal (as root, I know) also does "resolve" the clinging problem. What is supposed to be the problem with using "su" in a terminal, nobody has bothered to explain to me? Is my system compromised in some completely different way, because of me using "su"? I think "sudo" has finer grained control over subprocesses being granted root privileges? If you assume programs are full of undiscovered root exploits, then using "sudo" could be safer, privileges would not escalate? Well, starting from my next reinstall it will be "sudo" then. Debian 12.5, hostname "renaissance". uname -a follows: Linux renaissance 6.1.0-18-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.76-1 (2024-02-01) x86_64 GNU/Linux "su" is shorter than "sudo". Maybe this monologue would all have belonged to one of the Debian IRC channels. I've had difficulty working with colleagues in computer science since around who knows when. I believe what I'm doing here is doing my share in "digital forensics". Obviously I cannot communicate securely with anybody using this computer for now. I'll have to wait for an update to Debian, and do a full reinstall again. Time to start thinking of a good hostname, a pleasure.
Notice that this thread is broken into many part. (Perhaps because gmail does not support In-Reply-To in mailto: links) Output of the command to confirm the statement was not provided. From my point of view, something close to valid behavior was described. - If a file from an external drive is chosen for <input type="file"> then it is reasonable to expect that it can be used later when a form is submitted or an e-mail with the attachment is sent. Users are free to select another file, so eagerly reading the file to memory is not always reasonable. As a result it may be impossible to unmount the drive immediately. - File icons should appear in the file chooser and it may assume determining media types of these files. So precise description of steps and observed effects is necessary to make this bug report convincing.
stick. Ok, so I send Gmail to myself, with the single attached file "file4.gpg" on a mounted USB stick (icon menu,mount only, not opening an Xfce file browser). Even after I've received my own Gmail, the stick is unable to unmount (icon menu again), I get a graphical dialog (Xfce) saying the Gmail Inbox tab blocks it, that "there's still data that needs to be written to the device". Closing the Gmail tab will not help. I still get this: appe@renaissance:~$ lsof | grep -i KINGSTON x-www-bro 83803 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83807 glean.dis appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83809 IPC\x20I/ appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83810 Timer appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83811 Netlink appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83812 Socket appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83813 IPDL\x20B appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83815 HTML5\x20 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83817 JS\x20Wat appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83821 Cache2 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83822 Cookie appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83824 TaskCon~l appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83825 TaskCon~l appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83826 TaskCon~l appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83827 TaskCon~l appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83834 Worker appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83835 gmain appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83836 gdbus appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83845 x-www-b:d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83846 GLXVsyncT appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83847 x-www-b:d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83848 x-www-br: appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83849 CanvasRen appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83850 Renderer appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83851 WRWorker# appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83852 WRWorker# appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83853 WRWorker# appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83854 WRWorker# appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83855 WRWorkerL appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83856 WRWorkerL appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83857 WRWorkerL appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83858 WRWorkerL appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83859 Composito appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83860 x-www-b:d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83861 x-www-br: appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83862 ImageIO appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83863 Permissio appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83864 Breakpad appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83865 SandboxRe appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83866 IPC\x20La appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83870 QuotaMana appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83875 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83879 TRR\x20Ba appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83881 dconf\x20 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83887 StyleThre appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83888 StyleThre appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83889 StyleThre appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83891 GMPThread appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83893 ImageBrid appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83894 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83895 ProcessHa appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83904 AudioIP~v appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83905 AudioIP~a appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83906 AudioIP~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83920 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83921 WRScene~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83922 WRScene~d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83923 WRRende~c appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83942 URL\x20Cl appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83943 DOM\x20Wo appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83966 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83980 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83989 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83990 RemoteLzy appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83991 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84004 MemoryPol appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84008 glean.mps appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84015 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84048 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84098 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84129 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84133 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84135 LS\x20Thr appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84358 SwComposi appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84359 WRScene~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84360 WRScene~d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84361 WRRende~c appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84431 SwComposi appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84432 WRScene~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84433 WRScene~d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84434 WRRende~c appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84495 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84496 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84517 x-www-br: appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84801 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84915 SwComposi appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84916 WRScene~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84917 WRScene~d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84918 WRRende~c appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85044 x-www-br: appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85527 threaded- appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85979 BgIOThr~P appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85984 DNS\x20Re appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85985 DNS\x20Re appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86067 Backgro~o appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86068 DNS\x20Re appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86221 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86261 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86292 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86854 StreamTra appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86905 StreamTra appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg Only after closing Firefox the stick was able to unmount. HTH.
I rarely use gmail web UI. At least in the case of KDE, Firefox releases file descriptor a few seconds after compose dialog is closed. It seems even closing the tab is not necessary. It was a file on an internal drive, but I do not think it matters. [...] From my point of view it is in contradiction with the original complain: Isn't /media/appe/KINGSTON/noname/file4.gpg the file you attached? What are other 127 files?
stick. For my initial bug report, I just quickly did a "wc -l" on a long initial printout, so I was mistaken to claim those were distinct files, I don't know if they were. But now I think it is strange that the same file should be open so many times, it is wasteful at least and could lead to a cause for the clinging. In the dicussion in debian-user I think I said, that the clinging once lasted for about a minute, after which the unmounting completed. This probably led me to suspect that other files besides a less than 4 kB file (an earlier "file3.gpg") could have been accessed. If the problem is real, I think it should be easy to reproduce. Maybe it has to do with semi-legitimate virus scanning, or semi-legitimate concerns some might have about encrypted messages, and my data security personally is not at risk. If the file was on an internal drive, you would be unlikely to unmount it anyway. I continue to worry about my USB stick security. I have received advice, and have plans to improve my data security (including switching to the Chromium browser), but I still suspect that something is not right here. Thanks.
The file is opened once accordingly to the output you posted. It is how lsof reports usage in the case of multithread applications. Perhaps other ways to deal with files exist, but I am in doubts concerning real benefits for multithread applications related to privacy. As to access to other files, you may try to figure out if Firefox uses file picker provided by desktop-portal. Behavior may be different for flatpak/snap and deb packages. I am unsure if XFCE uses some desktop-portal implementation. This feature is intended to control what files an application may access, however in the case of deb package there is no barriers. You should know better if you have virus scanning software installed. From my point of view, some file indexer should be more probable variant (however it should ignore removable devices at least by default). You may find processes accessing specific files using autitd. What actions do you expect from Debian maintainers? (I am not a maintainer.)
maintainer.) I don't know much about Debian policies, so I don't expect anything further. I've read that "Debian takes security very seriously". I consider that I've done my best to report a possible problem, it's been taken seriously, and I've received plenty of advice. Thank you for your time! Best regards, Antti-Pekka Känsälä
Please, consider closing this bug by sending response to 1068122-done@bugs.debian.org Accordingly to https://www.debian.org/Bugs/Developer