4 ms·
>This exactly is the point. Wouldn't it be nice to just use apps without extra steps? It would make Linux better for non-experts. I don't run untrusted apps, a
by GhettoComputers 5y ago
>This exactly is the point. Wouldn't it be nice to just use apps without extra steps? It would make Linux better for non-experts.
I don't run untrusted apps, at the cost of crashing, and less overall functionality? Its cutting the nose to spite the face.
>You can’t even isolate X applications without running other X.org because there is no permission control once the application has access into socket, and with socket it can see everything. And you can’t really rework that. Sometimes you need to rewrite whole thing.
Not a real world scenario problem.
>Because the design is bad, it gets harder and harder to add new features. Fixing bug introduces two new ones. Complexity makes it hard to approach project and control everything. Red Hat has maintained it so many years with proper funding, otherwise who knows what would have happened.
Wayland design is... good? So it's taken over a decade to add a fraction of x.org features, and it still crashes? If it so simple and it still sucks, are you calling the programmers incompetent for not making the simple compositor functional?
- nicce 5y ago> I don't run untrusted apps, at the cost of crashing, and less overall functionality? Its cutting the nose to spite the face. The best practice is zero-trust; handle everything equally. You can't fully say by yourself which is really trustable, and if you are, then you are 0,01% of the actual population, and decision cannot be based on that. > Not a real world scenario problem. Of course it is, it is the biggest attack surface for normal application.
- GhettoComputers 5y ago>Of course it is, it is the biggest attack surface for normal application. What real cases have had this happen?
- shatteredgate 5y agoAre you asking when the X server has been exploited? There have been a lot of published root priv exploits published over the years. A few were just published yesterday: https://lists.x.org/archives/xorg/2021-December/060840.html https://lists.x.org/archives/xorg/2021-December/060840.html This type of thing is pretty common in old applications like this with a lot of hand-rolled networking code written in C.
- GhettoComputers 5y agoNo, I am asking about attacks in the wild. I know spectre and meltdown were possible to exploit, but its different from it existing as an attack, like a recipe versus a cooked meal. Thank you for your expertise in the thread.
- shatteredgate 5y agoI'm not sure what you mean by attacks in the wild. I don't have any news stories talking about how companies lost millions of dollars due to an X.org-based ransomware; but I hope you can see how it's not a good idea to wait for that to happen before fixing a security bug :)
- GhettoComputers 5y agoEncryption attacks are being mitigated by backups, but Linux servers don't usually use x.org or GUI do they? This might be why desktop linux isn't being adopted by business, but my point was that we hear of encryption attacks often, but not a single x.org attack that would make migration more pressing. Its living in a nuclear shelter when there is no nuclear threat, and living in an uncomfortable state out of paranoia. Linux is said to be safer in the public, but if x.org is that bad, is windows actually safer since it doesn't use x? I think its useful to mitigate problems, without real world examples its hard to care about invisible hypotheticals, especially at the cost of lost functionality.
- shatteredgate 5y agoI'm still not sure I understand. If there is a working proof of concept for the exploit that is published, would you still consider that an invisible hypothetical? To me, it's not, I would like to have those patched. As with meltdown and spectre there may be functional tradeoffs, but when significant money is at risk from security vulnerabilities then I'd usually expect security to win out. The attack vector for a trojan or ransomware can be a GUI system. It can be anything really, the malware just needs a way to get into the network and then it can cause more trouble and spread to more nodes.