Please dont use it. Firefox devs dont care. Flatpak restricts browsers from spawning "user namespace" sandboxes for filesystem isolation.
Chromium uses a fork server (zygote) and breaks when it cannot spawn these sandboxes. So developers created zypak, which allows to isolate processes using bubblewrap, the Flatpak sandbox.
Firefox just runs without a sandbox, and doesnt have a fork server, so nobody cares.
Without process isolation, you have less duplicated content. This saves space but IT IS INSECURE.
Please use a non-Flatpak Firefox version.
There is no reason why a "Zen Browser" should use less RAM than Firefox.
somehow get the IP address of that laptop all the time. There are dynDNS solutions like this where the client just needs to automatically download a certain file daily and you know his IP, my implementation is here.
have ssh access to root with a ssh key. The usual hardening, fail2ban, block using passwords
open the port for ssh on the clients system
If something goes wrong, login via ssh (you know the dynamically changing IP) and remove a directory or the entire user.
You cannot avoid that a user would copy files from there to a usb stick. Well you could, by using usbguard. Works really well in my experience, just prevent nonsudo users from adding new devices.
And then you need to prevent the user from booting another system, or taking out the SSD and reading it. TPM and boot lock is the right thing here, what Max-P wrote.
It is also a highly modified kernel, extremely reduced. They do all filesystem stuff in userspace for example, which is pretty cool. And they add a ton of garbage out of tree drivers.
If you want to host stuff, you probably want Termux. It is its own distribution but you may want to run a Debian proot inside Termux, which will have way more software and maybe also more reliably and fast security updates (heard that was a problem in Termux)
I2p meanwhile is just really good for anonymity. I think using it for messengers is the best use. I was able to find a bunch of stuff, and yes unlike the dark web this would mostly be also there on the clearnet, mainly because there is no such business on i2p I guess
Just random people offering services for free, a few pads, pastebins, fileservers
You can find quite some cool stuff actually, but I think the main advantage is using it for messaging
And unlike i2p, i2pd also doesnt really use much battery? I could totally keep that on all day
Cobol
💰💰💰💰💰