2 ms·
> Wayland can be keylogged, assuming the attacker can sneak some evil code into your .bashrc I’m not sure what scenarios are being invisioned here, but isn’t t
by SCdF 8y ago
> Wayland can be keylogged, assuming the attacker can sneak some evil code into your .bashrc
I’m not sure what scenarios are being invisioned here, but isn’t that absolutely something a nefarious app could do, because the app will be run as you, and you have write access to your bashrc?
As an example, since it’s fresh in my memory, if the folks who put dodgy cryptocurrency stealing code into npm packages had instead put this keylogger in there, that would have worked right? You run npm install, npm runs as you, the package runs as you, the package updates your bashrc.
- Sir_Cmpwn 8y agoYes, but that package could also do all sorts of other things, like encrypting your ~ and demanding ransom. It's not Wayland's problem to solve this - sandboxing is a separate matter. Wayland makes it easier to sandbox graphical applications but it is not a complete sandboxing solution.