Live data from Hacker News

Wayland vs. X – Overview

wayland.freedesktop.org

171–180 of 186 posts

Re: Wayland vs. X – Overview

#171

Earlier quoted context omitted.

You get that not every program invoked on a desktop necessarily comes by that way right? But that’s not actually the core problem. I trust you can do your own research as to what the security issues are, but as a starter here’s https://www.ctrl.blog/entry/clipboard-security.html These are very old issues and are some of the major reasons Wayland was started in the first place. May want to read up on what the problems…

I am well aware of what programs with access to my computer can do. That's why I use programs from sources I trust. I have zero interest in a low trust computing model because that comes with a cost to usability and performance, especially for power users but not also for others. I also get that most commercial software developers these days should be treated as adversaries because they will break any trust you place…

This is not practical for most people.

Eg, this completely excludes Steam. Laws aren't a good way to deal with the issue because they don't prevent damage. Try and sue some guy living in Russia.

Re: Wayland vs. X – Overview

#172

Earlier quoted context omitted.

libei looks useful. But IDK why libei is necessary to run Barrier with Wayland? For client systems, couldn't there just be a virtual /dev/input/XYZ that Barrier forwards events through And for host systems, it looks like xev only logs input events when the window is focused. Is xeyes still broken on Wayland, and how to fix it so that it would work with Barrier? With Barrier, when the mouse cursor reaches a screen bou…

> For client systems, couldn't there just be a virtual /dev/input/XYZ that Barrier forwards events through You seem to be asking for kernel thing, not something Wayland. But let's assume you wanted a protocol on top of Wayland to do this: Why can't arbitrary Wayland clients always see the mouse pointer, snoop on the keyboard, and inject keypresses? Because of security, by design. Why is it taking a bunch of work to p…

Sounds justified. How is the implementation?

Re: Wayland vs. X – Overview

#173
post #100

Earlier quoted context omitted.

> Under what threat model? Personally I have no interest in the zero-trust model needed for proprietary app stores and would rather not pay the cost. Under the threat model of websites using browser exploits to grab other data on your system? Or under the threat model of company policy or legislation not allowing you to handle confidential information on a system that can't offer even a basic guarantee of privacy.

> Or under the threat model of company policy or legislation not allowing you to handle confidential information on a system that can't offer even a basic guarantee of privacy. Last I'd checked, Windows had the same security issues as X, so it's unlikely to come up.

Untrue. Windows has permissions for capturing the screen which you have to enable on a per-application basis.

Next to that Windows has an even stronger permission model regarding DRMed content. But thats only to please movie studios it seems...

Re: Wayland vs. X – Overview

#174
post #100

Earlier quoted context omitted.

> Under what threat model? Personally I have no interest in the zero-trust model needed for proprietary app stores and would rather not pay the cost. Under the threat model of websites using browser exploits to grab other data on your system? Or under the threat model of company policy or legislation not allowing you to handle confidential information on a system that can't offer even a basic guarantee of privacy.

> Under the threat model of websites using browser exploits to grab other data on your system? Browsers already have multiple layers of sandboxes. You can always add another one to the browser if you are paranoid. Personally I prefer not running untrusted javascript in the first place (where I can avoid it). An exploit that gains control of the browser is already a doomsday scenario if you are using the browser for i…

There are more applications than a browser that can be exploited. Seems to me a secure GUI server is better than hardening thousands of applications.

I also prefer running trusted code, but that's not an option most of the time (for varying definitions of trust)

99% of the apps I use have no business with the contents of other apps I run so why allow it? Because X11 can't do anything about it is not a valid reason.

Re: Wayland vs. X – Overview

#175
post #167

Earlier quoted context omitted.

So you'd rather have TWO different bloaty slow sandboxes layered on top of each other, instead of one bloaty slow sandbox. Right.

I don't know what this means

The web browser is a sandbox, and it runs as an OS process, which is a sandbox.

I think their comment means you’d be better off targeting an OS level sandbox (maybe based on OCI(?), which means a different container for each OS kernel or breaking kernel change — new docker doesn’t run on old linux as it is).

If you chose the OS level sandbox correctly, that would probably be more cpu-efficient than the web browser.

However, that’s a big “if”, since most of the linux sandbox thingies take multiple seconds to spawn a process, and multiply memory usage by 10-100x.

Re: Wayland vs. X – Overview

#176
post #175
post #167

Earlier quoted context omitted.

I don't know what this means

The web browser is a sandbox, and it runs as an OS process, which is a sandbox. I think their comment means you’d be better off targeting an OS level sandbox (maybe based on OCI(?), which means a different container for each OS kernel or breaking kernel change — new docker doesn’t run on old linux as it is). If you chose the OS level sandbox correctly, that would probably be more cpu-efficient than the web browser. H…

No, I mean the other way around.

X11 sucks. Wayland sucks. Get rid of them both! But the browser's not going away, and it's open standards based and cross platform, and there's a huge amount of collaborative work and money and talent going into making it better and more powerful and more efficient and more secure across the entire industry and all platforms, unlike X11 and Wayland (which nobody gives a shit about outside of a few fanatical Linux desktop users), or even the Windows and Mac desktops and Android and iOS interfaces (which billions of people use every day, but are stagnant terribly designed dead-ends).

The browser is a sandbox, so why run it on top of another leaky inflexible insufficient outdated sandbox full of clumps of dehydrated urine and cat turds like X11 or Wayland, instead of directly on the hardware?

No modern desktop environment is complete without a browser, so since you're stuck with it, why not just use the browser itself as the desktop environment (or whatever user interface paradigm you choose to use), since you're never getting rid of the browser, and modern non-browser desktops aren't as flexible or powerful or extensible as a browser, and most useful applications have been ported to run in the web browser environment anyway, so they can run across many different platforms, and be easily distributed and efficiently used over the network (unlike Wayland or "modern" X11 apps).

I'm just surprised this seems to be so hard for some people to understand, in spite of the fact that I've been making the same argument for more than a decade, and provided many links to those arguments, because it seems extremely obvious and straightforward to me, and the technology is finally mature enough to pull it off.

Re: Wayland vs. X – Overview

#177
post #167

Earlier quoted context omitted.

So you'd rather have TWO different bloaty slow sandboxes layered on top of each other, instead of one bloaty slow sandbox. Right.

I don't know what this means

I included a lot of links to my previous posts over ten years explaining what it means in lots of detail with many different words and numerous examples and citations.

Did you read any of them? Did you read my other explanation below that I just wrote personally for your benefit? Does it make any sense to you?

Do you understand what I mean now, or do you need me to give you some more citations of other times I've written the same thing, because there are more. What was unclear, and did I leave anything out?

Do you have any more questions I haven't answered time and again and already gave you links to but you just didn't bother reading?

It's exasperating and insulting that you blithely dismiss what I wrote without saying what you disagree with or can't understand, but I promise you, it really is easy to understand and extremely obvious on its face, if you will just take the time to read what I wrote, before complaining you don't know what it means.

If you have time to complain, then you have time to read what I wrote and linked to, before complaining you don't know what it means.

If you're too busy to read, then please don't waste your and my time complaining you don't understand what you didn't bother to read.

Re: Wayland vs. X – Overview

#178

Earlier quoted context omitted.

On the fractional scaling side, precisely Wayland's advantage is that it works much better there than in Xorg. Regarding the rest, I run an Nvidia laptop under Wayland since early 2022 and it's been working flawlessly. It's true that I'm using one of the cleanest, most forward thinking distros out there: Fedora. On Ubuntu it had way more issues than on Fedora, though.

My past experiences with SuSE, Fedora, and Red Hat, RPM distributions, eventually experienced a corrupt repository that in each case took hours to fix. That's when I settled on Ubuntu in 2006 and haven't looked back.

I heard bad things about RPM before, but that was long ago. To be honest, I think by 2006 most issues were already over, and YUM was mostly on par with APT. Don't know what might happen in your specific case.

Re: Wayland vs. X – Overview

#179

Earlier quoted context omitted.

On the fractional scaling side, precisely Wayland's advantage is that it works much better there than in Xorg. Regarding the rest, I run an Nvidia laptop under Wayland since early 2022 and it's been working flawlessly. It's true that I'm using one of the cleanest, most forward thinking distros out there: Fedora. On Ubuntu it had way more issues than on Fedora, though.

I guess that’s a good way to think of Federora, forward looking. I always liked it for other reasons, but they do have just the right amount of forward focus. Ubuntu has a very different community to try and satisfy, so has to move slower.

Yes, I agree. I understand why RH splits Fedora and CentOS Stream.

Re: Wayland vs. X – Overview

#180

Earlier quoted context omitted.

On the fractional scaling side, precisely Wayland's advantage is that it works much better there than in Xorg. Regarding the rest, I run an Nvidia laptop under Wayland since early 2022 and it's been working flawlessly. It's true that I'm using one of the cleanest, most forward thinking distros out there: Fedora. On Ubuntu it had way more issues than on Fedora, though.

Ubuntu and Nvidia are difficult. We have a Linux work station and attempt to get an Nvidia card working (drivers anyway) failed. Its was confusing and even those with more skill/experience couldn't make it work. PopOS (which is a fork of Ubuntu) with Nvidia ended up working for us. Though I'm not sure if its X or Wayland.

Pop is X, they'll move to Wayland soon.

I am not sure what happened in the Ubuntu case, but maybe you guys should try Alma, RHEL or CentOS?

If Pop works well enough, power to you! I just believe it's not a standard in the industry.

Post reply on HN