Wayland works perfectly, except for when it doesn't

My point exactly, if a tool like him can get his issue to go viral what are the rest of us to do?

@wertigon Identified that xdg_dialog might be the solution to your window positioning issue you were complaining about.

I read about it and thought it had potential, and then started tracing out what needed completion before it actually works on end user machines. I don’t see a problem with that.

As far as actual statements from actual developers at JetBrains go, it is pretty clear they have some pretty strong biases, and when things like this get heated between different teams you can’t just “take their word for it”.

I’m trying to build context and research what it takes to get there. Sorry you don’t like it.

1 Like

I’m sure I’m going to miss some crucial context, but I’m not going to read that block of messages. Sorry if that causes someone to repeat themselves.

Where? Please provide a link and/or quote.

Based on? Here is the spec, click, read, learn.

It doesn’t appear to have anything to do with window position. But if it did, do you really think the Wayland team would have continued to work on the xx-zones, which they described as being developed to solve the problem we are talking about? Think critically here.

I’m getting a very “MBA without domain knowledge doing searches on google and wondering why things are hard vibe” here.

In summary

1: You made up a solution in xdg_dialog. We were talking about dialog placement, not xdg_dialog, not the same thing.

2: You presented the timeline of an unrelated extension as evidence the problem was already fixed.

Whoops. I’ve been using the wrong term all this time. :sweat_smile:

I don’t know where I got sidetracked.

I red Wertigons link to the XX-Zones merge request, and somehow got it mixed up in my my mind with xdg_dialog. I’m not even sure how that happened now. Maybe I was reading a different article and somehow got them mixed up.

My bad.

I am a long term Linux user for 30 years, but I am not a programmer, and I haven’t really played much with Wayland until the last month or so.

So, internal subprojects in Wayland are not things I am conversant in.

4 Likes

Mistakes happen, key is to learn from them an move on.

But at lease they won’t be able to look to see where any of the windows are.

Different layers, to prevent credential stealing you need to limit app permissions which is the realm of containers and flatpak.

Anything other then the system sort of level stuff really needs to be moved into sandboxes, but the history of this on the desktop has made people pretty lazy and people are always denying security or misunderstanding it.

Credential stealing would be harder if most user installed software didn’t just run as the user with all the same permissions making it easy to access and steal it.

This is again like complaining the lock on your front door does not prevent braking a window, sure but that is what protective films, bars ect over the windows are for.

Firstly let me apologize, the title is a little click batty. It’s the AUR so obviously the reach of this attack is rather tame compared to others we’ve seen.

You can yell and scream that this is the difference until you are blue in the face. The truth is that these attack vectors are separated by something more fundamental. Actual real world incidents VS hypothetical theory crafting.

The thing that prevents breaking a window is the laws surrounding the act. If someone just pics the lock, “sometimes,” that’s not as bad. So an apt analogy is someone using a sonic screwdriver on the front door lock VS tools from covert interments(not sponsored).

AI has proven pretty much all “Theory crafting” is practical and actual real world incidents.

“Nothing to worry about, it’s just a local exploit, you cannot use it remotely”… Yes, you can. And if you cannot see how, you need to start read up on Security at once.

1 Like

How do you define security? I define it as allowing what is to be permitted and blocking everything else. Do you agree?

That is not security.

That is whitelisting.

And that is like claiming you define carpentry quality by the speed the carpenter drives a screw with a screwdriver.

Whitelisting is a good idea, but hardly the Holy Grail of security.

1 Like

I didn’t fail to notice you have no idea what security is.

Listen, if the claim is that Sway and Hyperland have more of a property than Xlibre. We need a measurable definition to work with.

My measurement is features users care about and so my definition of security starts with this concept. If you want some other measurement to be deemed as more secure, you need to spell out what that is and importantly why anyone else should care.

:joy:

I work with embedded systems security (among other things) for a living.

On systems that, if they fail, someone might die.

So yeah, I can honestly claim… It is you who have no idea what security is.

3 Likes

Again, I didn’t fail to notice you can’t let yourself define it. I know that if you did your precious Wayland would quickly lose it’s standing as the secure option. So go ahead and just keep proving my claim correct that Xlibre is the secure option because it has many of the features users care about and that alone makes it the secure choice, because security is crucially defined as having the features users find important.

That is the beauty of Security. It does not have a true definition, as security is always a tradeoff with the use case.

Which you would know if you truly knew security. Security is a process, not a product. It therefore has no definition. Or rather, it has infinitely many definitions, depending on the product.

If carpentry was security, does the fact a hammer, a screwdriver, and/or a saw being involved, make the end product a beautiful cabinet the carpenter can be proud of?

No. Then what defines a beautiful cabinet the carpenter can be proud of?

Same thing with security.

1 Like

So can you help me then. Every time someone says Wayland is secure, can you help me let them know that “Security is always a tradeoff with the use case.”

It’s not a great definition, because I feel like it just pushes the issue off.

I’m pretty sure they have a good idea what security is. Wayland fixes several large holes in security that X11 had. It doesn’t mean it fixes all the OSes security issues, it’s just one component.

2 Likes

I read that as:

“X is undefined, Wayland fixes several large holes in X that X11 had.”

“Wayland fixes several large holes in undefined that X11 had.”

And that’s like what everyone has been saying over and over and I don’t get how they can make that claim. When I say “Wayland removes several large features in users pockets that X11 had.” It makes sense to me and I understand what I’m saying.

Edit: Both the sentences are about security, the latter is using my definition while the former used my best steelman of what others are saying. They refuse to tell me what X and security are so it’s impossible for me to discover what it is they are really saying.