Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

XZ utils backdoor could have exploited X11, but didn't. And the most common Wayland configurations wouldn't have protected people from the backdoored utility; only extremely paranoid and therefore esoteric setups might have.


> And the most common Wayland configurations wouldn't have protected people from the backdoored utility

If the attacker decided to backdoor an utility and make use of X11, it is most likely the backdoored utility will listen to keyboard events, read the bitmaps of other X11 clients.

And there's nothing that can stop the backdoor from doing so on X11...

Anyways, if you are saying the Wayland security policies are unneeded because there hasn't been an attack on X11 (this is the fundamental disagreement between us), consider the following: You don't install doors in your premise, because there hasn't been a case of burglary in your neighborhood?




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: