3 ms·
1) The UNIX security model puts users all in the same security domain. It's a given that a process running as user X can do whatever it wants with another proce
by Luke-Jr 8y ago
1) The UNIX security model puts users all in the same security domain. It's a given that a process running as user X can do whatever it wants with another process running as user X. I agree there may be better security models possible and even desirable in 2019, but at the end of the day, those are new and different security models. Does Wayland target standard UNIX security models, or does it require a specific new security model?
1b) The only really secure sandbox in 2019 appears to be complete hardware isolation. With Xpra, I can do this, and have windows from all my different security domains mapped on the same rootless display. I don't see any way to do the same with Wayland? (In fact, Xpra is buggy enough that if Wayland has a way to do this, it might be a killer feature and convince me to switch!)
2) Even GLES doesn't work without 3D acceleration stuff. I'm currently using a Radeon 7950, but only with the stock fbdev driver due to unresolved kernel bugs using the radeon driver. While my CPU can handle even full OpenGL with 3D games, I don't care to waste it on mere compositing.