Earlier quoted context omitted.
So the web is a better experience!
Unless you have to run the meeting.
Linux Zoom client proactively reading everything written to X11 clipboard
151–160 of 176 posts
Re: Linux Zoom client proactively reading everything written to X11 clipboard
#152Just run these things in your browser. Despite the dark design patterns that try to trick you into installing their desktop client, the web-based versions are fine.
not if you have to host meetings! the web versions are feature incomplete and don't support something as simple as screensharing with your camera overlayed in a corner (essential for recorded meetings). the zoom linux client consistiently locks up my entire computer whenever i copy from the chat. ridiculous.
Re: Linux Zoom client proactively reading everything written to X11 clipboard
#153I wish most Linux distributions had something like a standardized permission manager in which you enable the single policies apps are running with, similarly to what happens in Android (that has some Linux stuff under the hood). How hard would it be to have something like this? And I can’t even imagine the difficulty of gathering together the whole community around this standard...
Very. Both because of the technical issues others in this thread mentioned, and because Android and iOS had the unutterably massive advantages of starting from zero pre-existing software and having a single controlling authority.
The controlling authority allowed them to avoid problems related to consensus or people working on other priorities. Starting from zero allowed them to not worry about existing software (the closest thing to a controlling authority that Linux has cares a lot about backwards compatibility).
Re: Linux Zoom client proactively reading everything written to X11 clipboard
#154The "clipboard" as it is implemented in many (most?) operating systems today, only exists because it's a legacy idea that hasn't died. If it were freshly invented today, it would never get past even the most lenient privacy review. Think about the pitch for the feature: "So, we're going to make this in the OS, where the user can highlight anything in any application, invoke a command, and then that thing (which could…
No. You're assuming that you don't have control of your own computer. Think about the pitch for removing the feature, "So, we're going to make this in the OS, where visually disabled users cannot highlight anything in any application, can't move text between applications, cannot get the window title, cannot get the window tree, cannot have applications automate or know where other applications are, and basically they…
The paste intent doesn't seem antithetical to accessibility. A keyboard combination states intent just as effectively as a voice command, mouse input, or other source.
Re: Linux Zoom client proactively reading everything written to X11 clipboard
#155Earlier quoted context omitted.
Doesn't that preclude paravirtualization drivers? Seems like a major tradeoff for daily driver desktop stuff.
Xen prevents modifying ACPI data. It also passes obvious "Xen emulated drive", and similar for all hardware interfaces. Passes CPUID. Can't stop any of this with Qubes/Xen. But is trivial with Proxmox/KVM. Honestly, I wish there was a Qubes/KVM variant. It would fix every complaint, and enable running potentially malicious software (MS windows) and lie to it regarding hardware interfaces.
Relayed Issue: https://github.com/QubesOS/qubes-issues/issues/7051
Re: Linux Zoom client proactively reading everything written to X11 clipboard
#156Earlier quoted context omitted.
not if you have to host meetings! the web versions are feature incomplete and don't support something as simple as screensharing with your camera overlayed in a corner (essential for recorded meetings). the zoom linux client consistiently locks up my entire computer whenever i copy from the chat. ridiculous.
The web client definitely lacks features, but I fail to see how this is a client feature? You can share your screen and have your camera on at the same time. It's the recording server that decides how to composite those together.
Re: Linux Zoom client proactively reading everything written to X11 clipboard
#157Earlier quoted context omitted.
I don't get why a big company like Zoom, with presumably lots of users who are on Linux, only gives us a .rpm/.deb instead of a Snap/Flatpak. Seems like doing the minimum.
Snaps is a sure-fire way to only get used on Ubuntu. So that would be worse than distributing .rpm/.deb.
Re: Linux Zoom client proactively reading everything written to X11 clipboard
#158Re: Linux Zoom client proactively reading everything written to X11 clipboard
#159Earlier quoted context omitted.
Depends on how you use your computer. If you're mostly a developer/analysis terminal jockey with some browsing-- Qubes is a tremendous upgrade even if you don't care at all about the security properties: The normal qube model of template OS vms + ephemeral app overlays makes it a cinch to troubleshoot complex issues because you can scribble all over the VM (e.g. go ahead, monkey patch your system LIBC if you want!) a…
You make a very compelling argument. I've been thinking of at least trying it out before, but have been leaning towards it more and more over the years. A couple of questions though, if I could bother you with them? How is remoting performance e.g. via VNC/RDP or particularly via Moonlight+Sunshine (intended for gaming and such)? And how programmable is the configuration of Qubes? I like the idea of NixOS for example…
I've used RDP w/ remmina and found the performance somewhat poor but usable-- I think it does too much video writes, so it's more like playing a video I expect Moonlight+Sunshine would be equal or worse. Xpra seems to work better than RDP for me. I didn't try to optimize the RDP since I tried xpra and it was better. (I use it to control remote GUI amateur radio software like WSJTX)
There are workarounds I didn't mention for video performance, e.g. handing direct hardware access to a GPU to a specific VM. But this obviously has security consequences and I don't have much experience with it.
Qubes itself is very thin. The most popular template vms (that you actually run apps in) are Fedora and Debian. The qubes system vms run on Fedora. So I think on the VM OSes themselves there is no maintenance concern-- so for example, you're not dependent on the qubes project for packaging software generally. (Though you do use qubes produced templates of the OS installs-- as they have some configuration to handle the overlay filesystems, clipboard, file transfer, networking, etc).
There is also work that people are doing to make NixOS a first class app vm image and even people working on being able to use it for dom0.
The qubes maintained stuff is dom0 and the glue that handles stuff like copying between VMs, wiring up networking to VMs, etc. Most of it is python. I've found relatively little need to mess with that stuff. Its configured via text files that are processed via (mostly) python scripts. Beyond the active developers there is a user community that has a lot of experience doing fancy stuff with the infrastructure, like adding support for ephemeral VMs that exist only in ram (for anti-forensics). I think that speaks positively to the maintainability of the system.
Ultimately because qubes is a system of VMs based on commodity OS migrating OUT shouldn't be fundamentally hard.
FWIW, I migrated in to qubes (from Fedora) by making an app VM for my existing laptop, copying the home into it. Then initially running everything in that one VM. It's not a good way to use Qubes, but it had me full on it in a couple hours with no loss of capability. From there it was easy to start moving things into other VMs until I no longer used the original.
Re: Linux Zoom client proactively reading everything written to X11 clipboard
#160Earlier quoted context omitted.
Depends on how you use your computer. If you're mostly a developer/analysis terminal jockey with some browsing-- Qubes is a tremendous upgrade even if you don't care at all about the security properties: The normal qube model of template OS vms + ephemeral app overlays makes it a cinch to troubleshoot complex issues because you can scribble all over the VM (e.g. go ahead, monkey patch your system LIBC if you want!) a…
> But using a multipurpose computer without qubes is unsafe at any speed, worse than driving without a seatbelt. Could you elaborate on the odds of death and permanent disability occurring through use of unsecured general purpose computers? Because if not using qubes has the same risk profile as not wearing seatbelts I might feel like taking some measures
The serious point in my quip is that I've been a driver for over 30 years and yet to have a seatbelt protect me. I've been hit with computer attacks that qubes has limited. Might be kinda tricky to kill me from compromising my computer, at least today. Who knows about the computer.