8 ms·
That’s actually something you don’t want nowadays. A random app like xeyes should not be able to know mouse position at all times, for privacy reasons. (Unless
by anyfoo 2y ago
That’s actually something you don’t want nowadays. A random app like xeyes should not be able to know mouse position at all times, for privacy reasons. (Unless you very explicitly gave xeyes super-extra permission to do that.)
We’ve long stopped living in a world where you should need to fully trust every piece software that you run as your user on your computer. And even probably trustworthy software can go bad at an update due to supply-chain attacks.
- ChocolateGod 2y ago> A random app like xeyes should not be able to know mouse position at all times, for privacy reasons. (Unless you very explicitly gave xeyes super-extra permission to do that.) The thing about xeyes isn't that its privacy invasive, is that it shows that xeyes knows what you're doing in other clients. Got a gnome terminal root shell open? That's a privilege escalation method for any other client running on the desktop under Xorg. This itself, isn't really a problem, but chained with other attacks could be (e.g. browser escape).
- lupusreal 2y ago> Got a gnome terminal root shell open? That's a privilege escalation method for any other client running on the desktop under Xorg. This itself, isn't really a problem, but chained with other attacks could be (e.g. browser escape). Unless you're sandboxed up the ass, Wayland won't save you when that browser escape happens. Something I did 20 years ago to a friend as a prank that still works today on a typical Linux desktop with Wayland; wrap sudo to log the users password the next time they use it. I didn't use a browser exploit for that, but it can easily be done if you have write access to the user's environment however that happened. Wayland won't protect you from that sort of thing unless you're willing to commit to extensive sandboxing.
- bitwize 2y agoWayland is a critical step in sandboxing everything on the Linux desktop up the ass. Flatpak is also part of this effort. This is where desktop computing is headed; and why what Drew DeVault called "anti-Wayland horseshit" is actually derailing a secure, easy-to-use Linux desktop.
- dgfitz 2y agoIsn’t is possible to get something like mouse position from almost any stdlib of most languages?
- seba_dos1 2y agoNo, not really. Modern APIs usually don't even let you access that kind of information without additional privileges. Some older toolkits have functions that are supposed to do this, but it doesn't work everywhere.
- dgfitz 2y agoCan’t you get the cursor position from the windows c++ stdlib? Or like pyautogui? Or the Java stdlib?
- adzm 2y agoWindows' pointer position is available to even the most limited GUI application; it is not protected information. For win32 at least, I am not familiar enough to say that about the newer app packages which are much more locked down, but I would be surprised.
- anyfoo 2y agoHopefully only if the given app has focus.
- funcDropShadow 2y agoWhy? I want to have some applications that can always see the mouse cursor like, xeyes. Because that allows me to implement a better customized desktop environment.
- anyfoo 2y agoThen give that piece of code extra-special permissions. As I’ve said in another comment, the days where you downloaded your software from the sunsite or tsx11.ai.mit.edu FTP servers and could be confident that it and all its dependencies were trustworthy are unfortunately gone for a very long time.
- superkuh 2y agoIt really is something I want. But most people do live in your described world. That's the smartphone and "run's every javascript application sent to my web browser automatically" kind of computing security model. But there do exist personal behaviors of desktop operating system use where you can actually trust the applications installed and not put up walls between everything. And then things like keyboard/mouse sharing work, windows return to their places, and screen readers work. Those are all very important to me. For them I'm willing to browse with javascript temp-whitelist-only and many other such tedious things. What I'm trying to get across is that the need for that kind of intense security model, every process a threat, is not intrinsic to modern computing.
- kaba0 2y agoBut what’s the limiting factor of doing the sane and safe thing by default? The most popular operating systems all do that (ios and android), and they have carved out safe APIs for all of that to work. You can’t patch up a Swiss cheese after the fact. Is it hard to create standard APIs in a bazaar style of development? Yeah. But that doesn’t mean that it’s not the correct approach.
- realusername 2y agoI think their concern is valid, it's difficult to do something which is both secure AND not limited at the same time. Sure Android and iOS are secure but in practice they kind of suck for making anything non-standard which limits creativity and freedom. Can we have both a secure and extendable system? Maybe but none of them exist yet. I'm really worrying that Linux mainstream distros will become like Android or iOS.
- jcelerier 2y agoNo one wants to use android and iOS for serious desktop work though. Like it's cool when your only interaction with the device is consuming content, definitely not for creating.
- kaba0 2y ago
- kaba0 2y agoAnd an often under appreciated tenet of security — even a “good” software can be exposed to “bad” data, and you only need a bug (especially a memory bug, which is exceedingly common because linux userspace can’t get rid of c for the life of it) to have arbitrary code executed. Like, your pdf reader is surely not evil, but do you trust every single pdf file you open?
- account42 2y agoI expect my PDF reader to be secure. If the PDF format is too complex to implement safely then the renderer should be sandboxed in the reader itself instead of preventing me from scripting using xdotool and similar. And unless you fully sandbox your PDF reader then an exploit is going to have access to your user directory without any display server involvement anyway. X11 vs. Wayland doesn't even come into the picture.
- kaba0 2y agoIt shouldn’t complicate the program itself, everything should be sandboxed by default. And they should simply not have access to my home folder, it should be given access to a specific file only it is about to read.
- account42 2y agoThat severy limits the usability and even functionality that programs can implement. If you want a phone os then go use one but don't make Desktop Linux into one.
- ykonstant 2y ago> That’s actually something you don’t want nowadays. No, that is something you don't want. I and many others, do want this functionality.
- consteval 2y agoEven you don't want this, you only want it sometimes, for some apps. Which is exactly what they said. I mean, would you like VSCode tracking your mouse movements across the entire desktop and your keypresses and then sending them off to Microsoft? Probably not, so we're all in agreement.
- account42 2y agoI don't use VSCode or other user hostile programs like it so I don't care what kind of anti-features it enables. I don't want my actually useful tools hobbled in order to deal with such programs.
- anyfoo 2y agoxz wasn’t “user hostile”, and so weren’t countless other pieces of software affected by supply chain attacks. Nothing is hobbled if you can give it explicit permission (which you may well do on xeyes). The days where you downloaded your software from the sunsite or tsx11.ai.mit.edu FTP servers and could be confident that it and all its dependencies were trustworthy are unfortunately gone for a very long time.
- account42 2y agoThe xz-utils hack didn't care about the window system at all. It also hasn't actually caused any known damage and I'm sure if the american three letter agencies cared the perpetrator would have been dealt with by now. Project takeovers of that kind is not something regular users need to be worried about because the cost of pulling one off is too righ to waste on petty crime. It's yet another boogeyman and scaring people into giving up their computing freedom for "security" migh as well have been the goal of the operation.