3 ms·
The short reason is that if the user can do it, so can any application running as the user. I don't know about you, but I'd prefer my applications not be able
by chousuke 6y ago
The short reason is that if the user can do it, so can any application running as the user.
I don't know about you, but I'd prefer my applications not be able to inject and read inputs arbitrarily, though it may be that even stricter sandboxing is needed to make that a reality; Wayland being stricter than X11 is just one step along the way.
- Blikkentrekker 6y ago> though it may be that even stricter sandboxing is needed to make that a reality; Wayland being stricter than X11 is just one step along the way. It is not a situation of “it may be”; it is a situation of “it is”. Right now, it is useless as the security boundary on Unix and any other operating system is fundamentally the user and malicious software that runs as one's user can modify every file and process one owns anyway. I read one comment a while back by a developer that illustrated the fruitlessness of Wayland by saying that it is essentially a lock on a door, that stands in the middle of room, that one can simply walk around, claiming to add security.
- cycloptic 6y agoThat would be true if someone refused to use any form of sandboxing, however there are multiple sandboxing solutions available that the "door" works in combination with. That is the only real way to make this kind of security work on an ordinary Linux distribution, the approach used by Android where a new user is created for each application is not really feasible. There are also ways to sandbox X11, it's a bit harder to do, but you do have some options on how you'd like to do things.