3 ms·
As an aside, I decided to try out Cinnamon on my Debian box, and I actually found it to be a breath of fresh air. It's a modern approach to the non-bloated Gnom
by voteapathy 12y ago
As an aside, I decided to try out Cinnamon on my Debian box, and I actually found it to be a breath of fresh air. It's a modern approach to the non-bloated Gnome desktop of years ago. Reminded me a bit of when I first used xfce; very clean and straightforward. I feel Gnome and Unity try far too hard to dazzle and stand out, when it reality it all just gets in the way. No comment on KDE since I haven't tried it in a long time.
Some day though I'll go back to straight DWM, my old love.
- weland 12y agoI have very mixed feelings about some of the stuff Gnome is doing. Some of them are at least interesting from a certain point of view, like sandboxing applications. I get why this would be nice to have in corporate environments, and that brings money to Linux, which Linux does need. I also think it's solving problems at the wrong level for everyone else. (Selective) communication between sandboxed applications seems to be something they have no coherent framework for. Besides, as many Android applications show, savagely enforcing sandboxing has had questionable effects on privacy (as applications that really want your data will happily just request permissions to do everything and refuse to work otherwise). As for the security gains of such an approach, I'm skeptical about the effectiveness they add to an open source environment. What remains is offering additional protection against bugs (that e.g. allow otherwise unauthorized access). But proper desktop sandboxing is so incredibly complex that it's hard not to think a far more efficient approach would be fixing those bugs in the first place. For better or for worse, they're also experimenting with a lot of new approaches to UI. Which is pretty much how innovation happens -- something that computer desktops could use since everyone else is, at this point, imitating either Mac OS or Windows 95. However, an opt-out solution for users who are happy to encourage innovation, but would rather not be the victim of failed experiments every other release would be nice...
- madez 12y agoI have positive feelings about the effort of Gnome to sandbox applications. When you want to run closed applications it is obvious why you would want to sandbox. Even with open applications there is an additional security layer which is _very_ valuable because security related bugs are the normality, not the exception. The permissions system in android has had a good effect on privacy since you can deny access to private data for individual apps, and if need be to not make it crash you can just feed it empty or random data.
- weland 12y ago> Even with open applications there is an additional security layer which is _very_ valuable because security related bugs are the normality, not the exception. Considering that regularly writing secure servers or browsers seems to be beyond our reach for the moment, I think it's a safe bet to say that writing a secure sandboxing system is even farther beyond our reach. I doubt there is as much to gain in terms of security as we may think. > The permissions system in android has had a good effect on privacy since you can deny access to private data for individual apps, and if need be to not make it crash you can just feed it empty or random data. I know that Xprivacy does that in a way that makes me seriously question its security ( if these guys are correct, at least: http://android.stackexchange.com/questions/59093/how-does-the-application-xprivacy-give-fake-private-data-to-applications http://android.stackexchange.com/questions/59093/how-does-th... ). Not sure about PDroid and other solutions (my phone isn't supported by Cyanogen Mod). But it looks like a big pile of hacks over another big pile of hacks to me.
- madez 12y ago> Considering that regularly writing secure servers or browsers seems to be beyond our reach for the moment, I think it's a safe bet to say that writing a secure sandboxing system is even farther beyond our reach. I doubt there is as much to gain in terms of security as we may think. It is harder to breach two layers of security at the same time than one. > I know that Xprivacy does that in a way that makes me seriously question its security ( if these guys are correct, at least: http://android.stackexchange.com/questions/59093/how-does-th.. http://android.stackexchange.com/questions/59093/how-does-th.... ). This is a vague argumentum ad hominem against a third party. I don't see relevance to my arguments. > Not sure about PDroid and other solutions (my phone isn't supported by Cyanogen Mod). But it looks like a big pile of hacks over another big pile of hacks to me. I don't see your point here in regards to this discussion.
- weland 12y ago> It is harder to breach two layers of security at the same time than one. I think sandboxes are easier to realize than, say, a secure browser. I'm not questioning the advantages that sandboxing seems to have, in general. What I am questioning is the ability of the development team that couldn't fix Gnome panel for several years to write a secure sandboxing solution, even when relying on cgroups & co.. Either way, I'd much rather run sane applications that patch and pray that neither the application, nor the jail, have any really disastrous bugs. > This is a vague argumentum ad hominem against a third party. I don't see relevance to my arguments. Your argument about permissions and sandboxing on Android is that they help privacy because you can feed fake or empty data to the application. I never managed to do that on my phone (but didn't try that hard, either) so I thought I'd see if there was any progress in that field. Xprivacy was the first result that showed up. The way it does that, apparently, is by extending /system/bin/app_process to load a JAR file on startup, thus attaching itself to every process and replacing any method in any class. Yeah, no thanks. I can't wait to have the first catastrophic exploit in the Xposed framework making every single process vulnerable. I tried a couple of other solutions a while ago, but most of them ended up crashing or freezing applications.
- voteapathy 12y agoI absolutely don't disagree on your point regarding innovation. A number of people accused Windows 7 of taking UI ideas from KDE, which ultimately greatly improved their OS's usability. Still, a delicate balance needs to be found among innovation, enterprise requirements, and personal/community wants. Thankfully, at least covering the third group, with Linux there are often solutions to these experiments (though they might still end up being rather involved, such as creating your own solutions or moving on to a different window manager entirely). Yet if one doesn't like the Windows 8 UI approach, for example, the only real recourse would be to downgrade and hope things change for the better in the next release.
- digi_owl 12y agoI wonder if the whole sandboxing thing will go the way of polkit, doing its best when it is disabled. https://plus.google.com/+TheodoreTso/posts/4W6rrMMvhWU https://plus.google.com/+TheodoreTso/posts/4W6rrMMvhWU