4 ms·
>Of course it is, it is the biggest attack surface for normal application. What real cases have had this happen?
by GhettoComputers 5y ago
>Of course it is, it is the biggest attack surface for normal application.
What real cases have had this happen?
- shatteredgate 5y agoAre you asking when the X server has been exploited? There have been a lot of published root priv exploits published over the years. A few were just published yesterday: https://lists.x.org/archives/xorg/2021-December/060840.html https://lists.x.org/archives/xorg/2021-December/060840.html This type of thing is pretty common in old applications like this with a lot of hand-rolled networking code written in C.
- GhettoComputers 5y agoNo, I am asking about attacks in the wild. I know spectre and meltdown were possible to exploit, but its different from it existing as an attack, like a recipe versus a cooked meal. Thank you for your expertise in the thread.
- shatteredgate 5y agoI'm not sure what you mean by attacks in the wild. I don't have any news stories talking about how companies lost millions of dollars due to an X.org-based ransomware; but I hope you can see how it's not a good idea to wait for that to happen before fixing a security bug :)
- GhettoComputers 5y agoEncryption attacks are being mitigated by backups, but Linux servers don't usually use x.org or GUI do they? This might be why desktop linux isn't being adopted by business, but my point was that we hear of encryption attacks often, but not a single x.org attack that would make migration more pressing. Its living in a nuclear shelter when there is no nuclear threat, and living in an uncomfortable state out of paranoia. Linux is said to be safer in the public, but if x.org is that bad, is windows actually safer since it doesn't use x? I think its useful to mitigate problems, without real world examples its hard to care about invisible hypotheticals, especially at the cost of lost functionality.
- shatteredgate 5y agoI'm still not sure I understand. If there is a working proof of concept for the exploit that is published, would you still consider that an invisible hypothetical? To me, it's not, I would like to have those patched. As with meltdown and spectre there may be functional tradeoffs, but when significant money is at risk from security vulnerabilities then I'd usually expect security to win out. The attack vector for a trojan or ransomware can be a GUI system. It can be anything really, the malware just needs a way to get into the network and then it can cause more trouble and spread to more nodes.
- GhettoComputers 5y ago>I'm still not sure I understand. If there is a working proof of concept for the exploit that is published, would you still consider that an invisible hypothetical? Yes. If deployment is difficult and not applicable in real world settings it isn't really a threat, its like reading about the TouchID since the first iPhone 5S being tricked by copying fingerprints, or needing a bust of a person to trick FaceID. Do people still usually use it? Its a recipe, maybe even its cooked, but if nobody eats the poisoned food because it smells bad, I am not worried I might eat it. >then significant money is at risk from security vulnerabilities then I'd usually expect security to win out. In practice it sadly isn't true like the leaks of other people's data that constantly happens. I think updating browsers is a good idea, I think sandboxing apps can be safer, using a VM for some functionality could be useful too (if you run XP and malware detects its a VM, it doesn't even infect it). Basically I see most security issues as paranoia when its academics publishing hypothetical attacks that have never been seen in the wild, if they made super ebola in a lab or anthrax, I am not too worried about breathing it in. I would like it patched if the cost is worth it. Intel's was not, I disabled it, and religiously update my browser, my computer is faster, I have safety despite it never existing as an attack because it was easy to defeat.
- shatteredgate 5y ago>its like reading about the TouchID since the first iPhone 5S being tricked by copying fingerprints, or needing a bust of a person to trick FaceID That's not really comparable, these are trivial exploits that can probably be targeted with a 100-line program, or less. >In practice it sadly isn't true like the leaks of other people's data that constantly happens. I've known many security people who take their jobs very seriously. If they weren't doing their jobs, you'd see quite a lot more data breaches than you do now :)