3 ms·
Right, if you already have malware running on your system, all bets are off. However, I'm sure you're aware that large applications like Chromium have tons of v
by trulyrandom 8y ago
Right, if you already have malware running on your system, all bets are off. However, I'm sure you're aware that large applications like Chromium have tons of vulnerabilities, which is why they come with a sandbox to protect against exploitation. X11 is one of the biggest holes in these sandbox solutions. Replacing X11 with Wayland would plug this hole. I'd argue that security is something the average user cares about.
- pmoriarty 8y agoIf your web browser is compromised, that's malware running on your system right there. A compromised web browser doesn't need X to control the rest of your system. It can usually already write all over your system and perform all sorts of other attacks, including substituting applications, paths, LD_LIBRARY_PATH, etc.. not to mention try kernel exploits and the like -- not that they'd need to on a single-user system, as they could just get your sudo password by one of the other means mentioned above, all without touching X. Anyway, if a typical user's browser is compromised, they're already completely screwed, as they typically access their online banking and webmail through it. Once again, the attacker does not need to touch X to get access to any of that. To me it still sounds like Wayland's security model is trying to solve a niche problem that most X users don't really suffer from -- and charging an arm and a leg for it.
- trulyrandom 8y ago> It can usually already write all over your system and perform all sorts of other attacks Not necessarily. Properly sandboxed applications like Chromium have a seccomp filter, separate pid/user/etc namespaces and bind mounts setup to isolate themselves from the rest of the system as much as possible. > Anyway, if a typical user's browser is compromised, they're already completely screwed It really depends on which part of the browser is compromised. Again, Chromium has some pretty good isolation. Having one malicious website exploit a vulnerability does not necessarily mean the attacker gets access to any of the other browser data.
- pmoriarty 8y agoIf the browser as a whole has not been compromised, then internally it should be able to deal with the clipboard the same what that Wayland deals with it. For instance, only the currently focused tab should have access to the X clipboard.
- jniedrauer 8y ago> If your web browser is compromised, that's malware running on your system right there. This is a bit naive. Browsers execute malicious javascript on your system all the time. A V8 sandbox escape is worth retirement money for a reason.