@NebulaTide @thedaemon @claudiom For sure!
Every once in a while, if a project/task seems to necessitate it, I'll go as far as running #Firefox or #UngoogledChromium as another unprivileged sandbox user in a #Xephyr display using my own [rudimentary] #Xsunaba utility. I _still_ wouldn't trust it any further than I can throw it, and it's only marginally safer and less trouble than spinning up a VM.
Every added layer of the onion is another that someone else has to bite through. More tears?
