logoalt Hacker News

account42today at 10:45 AM2 repliesview on HN

Are you aware that if software misuses the capabilities its given by the system you can choose to stop using that software?


Replies

orbital-decaytoday at 12:59 PM

You can't do anything about a compromised app or JS from a random website. I always find it weird when people attack Wayland's security model, more isolation is obviously a great idea, as demonstrated by supply chain attacks in the recent decade.

It's that Wayland's design, implementation, their attitude, and everything else about it is terrible. It could have been implemented without compromising on features or convenience by explicitly specifying minimalistic controlled side channels in their security model from the start, instead of shifting it onto ad-hoc implementations. And of course the windowing system is already too large of an attack surface. Many people are thinking about going full Qubes due to the current realities, while the others live in denial and call even window isolation "paranoia". Fascinating.

show 1 reply
teo_zerotoday at 12:04 PM

True. But it's often all or nothing: you can't surf the web without the ads.