I've been enjoying your responses a lot! I just wanted to express my gratitude one more time!
Thanks man, means a lot these days.
What I am afraid of is how secure (continued) operation within containers would be. So even if Brave (or whichever browser for that matter) is not the culprit, the rest of the container environment might endanger the rest of my system.
If your container for brave is running but the browser itself is closed, there is no way for to happen within the container because the software that would be connected to the internet is closed/quit/stopped. In fact that container should be reported as down by whichever management subsystem is provided by said container (portainer, lxd, systemd-namespaces, etc)
So I've mostly been using well-integrated 'pet-containers' like the ones known from Distrobox (with a relevant recent feature). Aside from those I've been exposed to the earlier article and to this video. These 'expositions' have made me go from a Distrobox-enjoyer to a pessimist that doesn't dare to come close to them until I've better educated myself on them
I think you should look more into what containers are and can do, You previously said that your system is low power but distrobox is making loads of of full OS/distro containers which for the most part act like a VM. Distrobox is a good way to test drive a distro OR allow a dev to ensure the app they've made works on their target distro's for chosen use case.
All you really need to do is run a single application within a container, not a whole distro!/os Why do I say this? Well resource consumption for one and why replicate an entire distro/os when an app can be run inside a container: https://bacchi.org/posts/brave-in-docker/
Additionally I spoke about attack vectors, running another distro/OS inside a docker may well have samba, ssh running by default, If the container for that is not firewalled that is is an attack vector that will allow RCE and exploits be run inside that container!
Aside from those I've been exposed to the earlier article and to this video.
The first minute of that video talks of nginx webserver image, That is a webserver running inside a container, with distrobox you have the rest of the OS inside the container as well as nginx. Do you get what I say now?
I suggest you use the above link I gave to look into running just a browser within a container, drop distrobox (unless you need to test drive distros) and learn about running a single application within a container, when you can do that find a container framework that provides the security you want/like then run your "untrusted" applications in containers and rejoice with a slightly faster machine.
EDIT: Additionally wolfi is based on Alpine, This is a popular server distro, If you want to install wolfi you'll need to know how to install alpine, which is similar to installing gentoo as it uses bootstrap images, don't be surprised if the desktop experience is a bit ...erm lacking as that is not the focus of alpine or wolfi ! Good luck
Chromite/Bromite is primarily an android browser, even on windows it looks and behaves just like a mobile app.
Whilst I like the feature set as an alternative to Brave the fact they refuse to fix the PWA situation as it's "Of no interest" to the dev is a no go for me.