4 ms·
Interesting that this comes up again with Ubuntu Trusty continuing to retain Xorg. Is anyone familiar enough with Mir and Wayland to comment on how those packag
by ecma 12y ago
Interesting that this comes up again with Ubuntu Trusty continuing to retain Xorg. Is anyone familiar enough with Mir and Wayland to comment on how those packages approach this kind of thing?
- htns 12y agoBoth fix it by making snooping and spoofing unavailable by default. An application only has access to its own windows, inasmuch processes are properly isolated in other aspects as well. Typically they aren't, e.g. very few distros have any "single user level" safeguards for ~/.bashrc. Qubes solves that problem as well.
- flogic 12y agoDoes it actually matter? For the average desktop, everything of monetary value will be under the main user account. Which is generally also the account used to touch the internet.
- ecma 12y agoI think it does matter. Defence is relevant at almost every level of software. If a window manager can make smart design choices to make it non-trivial to implement bad software for the interfaces it serves, it's an obvious choice IMO.
- XorNot 12y agoThis is a problem which needs to be fixed, as cryptolocker demonstrates. We really need some hard boundaries set between non-interactive and interactive requests to open files. Sensible ones too - not "ask about every file", but maybe "grant process access to this folder in my documents folder, without recursive access". Even better would be "fire this backup utility first, then grant access".
- antocv 12y agoThis could be implemented for ~ using a fuse.