3 ms·
I'm not trying to claim that X is secure as is. The claim I'm making is: 1. There is nothing fundamentally insecure about the design of X that couldn't be fix
by wmanley 2y ago
I'm not trying to claim that X is secure as is. The claim I'm making is:
1. There is nothing fundamentally insecure about the design of X that couldn't be fixed with a bit of effort.
2. The effort required would be significantly less than what has gone into Wayland over the last 16 years.
Fixing the security of the system certainly would involve changes to more than just xorg. Anywhere there is a security boundary you'd need to make modifications - but that's OK, most of these security boundaries are younger than wayland anyway.
This discussion of $DISPLAY seems like distracting minutiae. Sure it's a medium size problem that would need solving, but that's all it is.
To address your specific point: it could be the responsibility of the window manager to set $DISPLAY to a less powerful socket when starting processes. Ultimately it doesn't matter though, because if the display server isn't doing some sort of sandboxing then the spawned process can just ptrace xorg and do whatever it wants. X being secure only matters in the presence of a security boundary and in that case it would be the responsibility of whatever is setting up that boundary to create a less privileged socket. Whether that be ssh or flatpak or whatever.
- yencabulator 2y agoSo now we've reached the point of "you could secure X11 if you changed everything". Sure, fine. Once again, for emphasis: nobody has stepped up to do that, in the history of X (outside of proprietary products, of unknown quality). Wayland is not some outsider project competing against X11. It's the people who were developing Xorg, saying they're fed up with X11 and need a clean slate to fix its problems. Here's my unpriviledged user trying to ptrace my Wayland compositor running as me: strace --syscall-limit=1 -p 697351 strace: attach: ptrace(PTRACE_SEIZE, 697351): Operation not permitted Nearby, I have a Chromebook where a potentially hostile virtual machine can display Wayland windows seamlessly on the host. The worst the VM can do is fill bitmaps with offensive imagery. In a world where the people doing the work switched to developing the Wayland ecosystem, arguing about a "could" that requires changing every window manager seems like a guarantee X11 will not get improved. Feel free to put effort into it...