This is no longer being done, at least not at the moment. Because of how the virtual mouse cursor works, it would be necessary for the core kloak process to make the raw input event stream visible to the child even if we were to do this, so this split would provide little to no anonymity improvements. It would prevent getting any form of root access via arbitrary code execution within the kloak process, but the sandbox on the kloak process is pretty severely limiting, so it’s unlikely the crippled form of “root” access one would gain by compromising kloak would be at all useful, not to mention the fact that we have a lot of hardening features enabled on the kloak binary to make it a major headache to compromise in the first place.
2 Likes