4 ms·
Straight from the horse's mouth: https://www.x.org/wiki/Development/X12/ https://www.x.org/wiki/Development/X12/ > In short, X11 was designed for a different
by rom-antics 4y ago
Straight from the horse's mouth:
https://www.x.org/wiki/Development/X12/ https://www.x.org/wiki/Development/X12/
> In short, X11 was designed for a different era of computing.
> This is not to say that there's an X12 project. There isn't. But if one day there is...
> Systems need to be secure. X12 needs to be designed with security in mind.
Do you think the Xorg devs are spreading lies about Xorg?
- destructionator 4y ago> Do you think the Xorg devs are spreading lies about Xorg? Some are, yes, this is incontrovertibly true. But this one? You should hit the "history" button that's in the corner of every wiki. That page hasn't been edited at all since 2013, imported from some other document written I don't know when, and literally the only thing it actually says about security is that "needs to be designed with security in mind". What does that mean? What specific shortcomings have they identified?
- vengefulduck 4y agoThe fact that any Xorg client can become a key logger without any user input or authentication is a pretty big security hole imo. By design Xorg has no isolation between clients so they can all read each others input, control others windows, and inject keystrokes into other applications. That’s unacceptable in the modern age and makes any attempt at sandboxing or separation of privileges for GUI applications completely pointless.
- csdvrx 4y agoSimple solution: isolate, by running 1 X server per client (or set of clients if you want gimp and krita in the same sandbox)
- thewataccount 4y agoIs there any tutorials/examples of how to do this?
- seabrookmx 4y agoApologies for not answering your question directly, but I'm pretty sure this is what XWayland does to allow for compatibility of X apps ontop of wayland.
- destructionator 4y ago> The fact that any Xorg client can become a key logger without any user input or authentication is a pretty big security hole imo. This "hole" doesn't exist. For an X client to capture input, it must be authenticated by either the unix user permission or by an access control list (where the default is to deny). Individual clients can also be marked untrusted which sandboxes them to some extent (though not as much as using a separate X server of course). I'll grant that in practice, most the time these restrictions are very lax... in part because they can break some applications. But at the same time, in practice, it doesn't seem to matter that much since either you're running things you trust anyway or if a malicious application has access to your X connection they also have access to all your other files so you're in trouble anyway.
- nisegami 4y agoI imagine it's mostly the issue related to applications having too much access to thinks like the keyboard and other windows without a permission system? That's a large part of what makes Wayland different from X11.