6 ms·
I never forgot and in most respects it was far more elegant than X which always seemed a very poor design. What I especially liked about MGR was that remoting
by FullyFunctional 5y ago
I never forgot and in most respects it was far more elegant than X which always seemed a very poor design.
What I especially liked about MGR was that remoting was dead simple; it worked as long as your terminal worked so ssh somewhere and start an app - it just worked (AFAIR).
X had remoting is a primary feature, but it's hackish and awkward and filled with issues (you really don't want to know what happens under the hood of 'ssh -Y').
However, neither really works for application that needs massive updates at a fast framerate, so hopefully Wayland will work better.
- glandium 5y agossh didn't exist when either X or MGR were created.
- FullyFunctional 5y agos/ssh/rsh/
- DonHopkins 5y ago>ssh somewhere SSH was introduced in 1995, so back in the 80's you just used good old insecure unencrypted rlogin or telnet, and maybe Rick Adam's SLIP over a modem in the late 80's. https://en.wikipedia.org/wiki/Serial_Line_Internet_Protocol https://en.wikipedia.org/wiki/Serial_Line_Internet_Protocol
- FullyFunctional 5y agoSure ssh didn’t exist, but as best I recall rsh did at the time I used MGR and worked much the same way sans the security.
- tinus_hn 5y agoNo, you can just tell X clients (applications) to present themselves on a remote X server, either with no security or with an access key. It’s an unencrypted connection managed by the application itself and the X server. Sounds like a helpful feature until you realize that any X client can act as a keylogger for the whole session. If you use SSH, it presents a fake X server local to the client that works as a proxy and tunnels the communication through the SSH connection. But as far as the client sees, it’s connected to a local server.
- DonHopkins 5y agoI was referring to running MGR clients over rlogin/telnet/slip, not X clients. Yes I know X clients talk to the server via unencrypted connections over the network -- I developed a multi player X11 version of SimCity whose client connected to multiple players' servers at the same time. But as FullyFunctional rightly pointed out, X11 networking is "hackish and awkward and filled with issues". So I removed the multi player networking feature when I ported SimCity to the OLPC XO-1 Children's Computer for kids to use, since it was unthinkable to expect kids to deal safely with X-Windows network security using xauth or setting up ssh tunnels. https://www.youtube.com/watch?v=_fVl4dGwUrA https://www.youtube.com/watch?v=_fVl4dGwUrA https://www.youtube.com/watch?v=EpKhh10K-j0 https://www.youtube.com/watch?v=EpKhh10K-j0 David Chapman describes some of the problems with X-Windows "MIT-MAGIC-COOKIE-1" authentication in the book "Unix-Haters Handbook" chapter "X-Windows Disaster" section "Myth: X Makes Unix 'Easy to Use'": https://donhopkins.medium.com/the-x-windows-disaster-128d398ebd47#97a7 https://donhopkins.medium.com/the-x-windows-disaster-128d398... Date: Wed, 30 Jan 91 15:35:46 -0800 From: David Chapman <zvona@gang-of-four.stanford.edu> To: UNIX-HATERS Subject: MIT-MAGIC-COOKIE-1 For the first time today I tried to use X for the purpose for which it was intended, namely cross-network display. So I got a telnet window from boris, where I was logged in and running X, to akbar, where my program runs. Ran the program and it dumped core. Oh. No doubt there’s some magic I have to do to turn cross-network X on. That’s stupid. OK, ask the unix wizard. You say “setenv DISPLAY boris:0”. Presumably this means that X is too stupid to figure out where you are coming from, or unix is too stupid to tell it. Well, that’s unix for you. (Better not speculate about what the 0 is for.) Run the program again. Now it tells me that the server is not authorized to talk to the client. Talk to the unix wizard again. Oh, yes, you have have to run xauth, to tell it that it’s OK for boris to talk to akbar. This is done on a per-user basis for some reason. I give this ten seconds of thought: what sort of security violation is this going to help with? Can’t come up with any model. Oh, well, just run xauth and don’t worry about it. xauth has a command processor and wants to have a long talk with you. It manipulates a .Xauthority file, apparently. OK, presumably we want to add an entry for boris. Do: xauth> help add add dpyname protoname hexkey add entry Well, that’s not very helpful. Presumably dpy is unix for “display” and protoname must be… uh… right, protocol name. What the hell protocol am I supposed to use? Why should I have to know? Well, maybe it will default sensibly. Since we set the DISPLAY variable to “boris:0”, maybe that’s a dpyname. xauth> add boris:0 xauth: (stdin):4 bad “add” command line Great. I suppose I’ll need to know what a hexkey is, too. I thought that was the tool I used for locking the strings into the Floyd Rose on my guitar. Oh, well, let’s look at the man page. I won’t include the whole man page here; you might want to man xauth yourself, for a good joke. Here’s the explanation of the add command: add displayname protocolname hexkey An authorization entry for the indicated display using the given protocol and key data is added to the authorization file. The data is specified as an even-lengthed string of hexadecimal digits, each pair representing one octet. The first digit gives the most significant 4 bits of the octet and the second digit gives the least significant 4 bits. A protocol name consisting of just a single period is treated as an abbreviation for MIT-MAGIC-COOKIE-1. This is obviously totally out of control. In order to run a program across the fucking network I’m supposed to be typing in strings of hexadecimal digits which do god knows what using a program that has a special abbreviation for MIT-MAGIC-COOKIE-1?? And what the hell kind of a name for a network protocol is THAT? Why is it so important that it’s the default protocol name? Fuck this shit. Obviously it is Allah’s will that I throw the unix box out the window. I submit to the will of Allah.
- a-dub 5y agoif the sysadmin were any good, at least there might be s/keys for initial authentication.
- swills 5y agoOr maybe Slirp: https://en.wikipedia.org/wiki/Slirp https://en.wikipedia.org/wiki/Slirp
- tibbetts 5y agossh -Y came late. For a long time as I recall you just let your X windows server listen on the network and any other machine could just send it windows to draw. You could just manually set the environment variable on the remote machine. That was still how stuff worked at some banks in 2004, because they were slow to adopt ssh. Wide open connections to X servers enabled both impressive hacks and impressive trolling.
- tyingq 5y agoI remember one troll-your-friends app that would (at random intervals) watch as the mouse pointer approached a window, and then warp it into a random spot.