4 ms·
> the likes of Xorg really aren’t designed for that use case. Bullshit. Would be nice if people were to stop spreading these outright lies.
by destructionator 4y ago
> the likes of Xorg really aren’t designed for that use case.
Bullshit. Would be nice if people were to stop spreading these outright lies.
- chrismorgan 4y agoI’m curious how you think it an outright lie. I’m speaking of the consequences of Xorg’s basic lack of isolation (because it wasn’t designed for use cases where that matters): that granting access to the X socket allows you to inspect, intercept and modify inputs and outputs for things like key strokes, window contents (yours or others’) and clipboards.
- deleted 4y ago[deleted]
- destructionator 4y ago> I’m speaking of the consequences of Xorg’s basic lack of isolation (because it wasn’t designed for use cases where that matters): that granting access to the X socket allows you to inspect, intercept and modify inputs and outputs for things like key strokes, window contents (yours or others’) and clipboards. This is not true! Both the protocol and the implementation allow for significant separation of server permissions (for example, notice the difference between ssh -X and ssh -Y), and the peer-to-peer nature of things like clipboard means it is quite easy to deny requests on an application level if they're written for it.
- anthk 4y agoXTerm has basic keyboard locking support.
- rom-antics 4y agoStraight from the horse's mouth: https://www.x.org/wiki/Development/X12/ https://www.x.org/wiki/Development/X12/ > In short, X11 was designed for a different era of computing. > This is not to say that there's an X12 project. There isn't. But if one day there is... > Systems need to be secure. X12 needs to be designed with security in mind. Do you think the Xorg devs are spreading lies about Xorg?
- destructionator 4y ago> Do you think the Xorg devs are spreading lies about Xorg? Some are, yes, this is incontrovertibly true. But this one? You should hit the "history" button that's in the corner of every wiki. That page hasn't been edited at all since 2013, imported from some other document written I don't know when, and literally the only thing it actually says about security is that "needs to be designed with security in mind". What does that mean? What specific shortcomings have they identified?
- vengefulduck 4y agoThe fact that any Xorg client can become a key logger without any user input or authentication is a pretty big security hole imo. By design Xorg has no isolation between clients so they can all read each others input, control others windows, and inject keystrokes into other applications. That’s unacceptable in the modern age and makes any attempt at sandboxing or separation of privileges for GUI applications completely pointless.
- csdvrx 4y agoSimple solution: isolate, by running 1 X server per client (or set of clients if you want gimp and krita in the same sandbox)
- thewataccount 4y agoIs there any tutorials/examples of how to do this?
- seabrookmx 4y agoApologies for not answering your question directly, but I'm pretty sure this is what XWayland does to allow for compatibility of X apps ontop of wayland.
- destructionator 4y ago
- deleted 4y ago[deleted]