3 ms·
Why does this say (2021) when the last commit was in 2014?
by jstarks 6y ago
Why does this say (2021) when the last commit was in 2014?
- Jkvngt 6y agoStill works great, too! How long until Wayland developers fix this, another seven years?
- theamk 6y agoUgh, they cannot fix it because this is not something that wayland can fix at all. Look, if you have user access to the account, you can get its data. Even if you somehow make Wayland 100% secure, you can still replace “firefox” shortcut with malicious version which also steals all your passwords. No windowing aystem involved at all.
- Jkvngt 6y agoBut bleargh, why do Wayland proponents always seem to bring up keyloggers? That’s icky.
- zlynx 6y agoThe X11 protocol allows any client connected to the server to become a keylogger or insert input events. So, even a X11 client trapped in a sandbox or another user account has full access.
- theamk 6y agoDo you mean "opponents"? For example, this post is the only post on HN about wayland keyloggers, and it is clearly written by Wayland opponents.
- dralley 6y agoBecause the X11 protocol itself enables every X app to keylog every other app without any "hacks" involved, which is what this is. It's the difference between having a poor quality lock on your door and having no door at all.
- bitwize 6y agoThe X11 protocol doesn't enable this, even if the most widely used X11 implementation does. An implementation could isolate clients by dropping events and returning blank rectangles for GetImage calls.
- cycloptic 6y agoIMO the main problem there is that the UX around dropping events and returning blank rectangles is bad. We have the tools to design other protocols centered around a real security architecture that can communicate intent properly and doesn't need to return fake data.
- bitwize 6y agoIt's probably a better idea to throw BadWindow or BadDrawable when an untrusted client queries about windows or pixmaps it doesn't own. As for dropping events... the idea is to isolate clients, such that it's as if X resources not owned by the client do not exist to the client. If the UX of the client depends on violations of that rule, then it's either a program like a window manager that should go on a trusted whitelist, or it's up to something nasty. Note that Firejail does this by using Xpra as a proxy to the real X server.
- cycloptic 6y agoIMO, X11 is practically unusable without NX/Xpra, but it has other UX issues and it still doesn't do exactly what you'd want. Throwing a protocol error is also bad UX. There's no way to present that to the user other than saying "hey this didn't work, go fix it in some other system-dependent place that I may or may not know about."