4 ms·
In my mind, if you're running potentially-compromised code on your machine, you're already hosed and the display server isn't going to protect you.
by superdisk 2y ago
In my mind, if you're running potentially-compromised code on your machine, you're already hosed and the display server isn't going to protect you.
- bobmcnamara 2y agoAh the binary secure/unsecure straw man.
- orangeboats 2y agoNot really. You can run potentially-compromised code in a sandbox. X11 is unsandboxable though since X11 programs can see each other freely through the display server.
- hedora 2y agoIt’s been under a month since Linux patched a zero-day that made it trivial for any program to get root.
- orangeboats 2y agoI don't see how this is related to the topic at hand. A zero-day attack can be patched, but the security issues with X11 are intrinsic to the protocol itself and are nontrivial to fix.
- welterde 2y agoThat is not true. There are extensions to the X11 server that can resolve many of the security issues, but almost no one cares enough to use them. If you are doing X11 forwarding via SSH it defaults to a more restricted configuration that only allows a more restricted access to the server (no direct sniffing of the input devices for instance).
- nextaccountic 2y agoDo you browse the internet with scripts on? (Javascript and Wasm). It is fully untrusted code that runs in a sandbox. Do you expect that random webpages are ableto steal all data from all applications you run, and all files you have? Including passwords etc.
- pabs3 2y agoSpectre was possible to attack from JavaScript: https://leaky.page/ https://leaky.page/