Earlier quoted context omitted.
> Pipewire runs under the pipewire user, managed by systemd or OpenRC. Which means any of their managed processes can start a new pipewire user process. The box I checked has no pipewire user and it's running under the account I logged in with. > A local priv-sec is one exploit [0] away from a remote one. That only matters for accounts that talk to the outside world. If I'm the only user, I'm not depending on securit…
If you play sound, such as from a browser, or a file you didn't record yourself, then your account is talking to the outside world.
Maybe I wasn't clear. I'm saying exactly one account has meaningful exposure to the outside world, and it's the only one with valuable files. Not none, but also not multiple. It's effectively single user from a security perspective.