this post was submitted on 18 Sep 2023
91 points (100.0% liked)

KDE

5110 readers
27 users here now

KDE is an international technology team creating user-friendly free and open source software for desktop and portable computing. KDE’s software runs on GNU/Linux, BSD and other operating systems, including Windows.

Plasma 6 Bugs

If you encounter a bug, proceed to https://bugs.kde.org, check whether it has been reported.

If it hasn't, report it yourself.

PLEASE THINK CAREFULLY BEFORE POSTING HERE.

Developers do not look for reports on social media, so they will not see it and all it does is clutter up the feed.

founded 1 year ago
MODERATORS
 

Wayland. It comes up a lot: “Bug X fixed in the Plasma Wayland session.” “The Plasma Wayland session has now gained support for feature Y.” And it’s in the news quite a bit lately with the announcement that Fedora KDE is proposing to drop the Plasma X11 session for version 40 and only ship the Plasma Wayland session. I’ve read a lot of nervousness and fear about it lately. So today, let’s talk about it!

top 45 comments
sorted by: hot top controversial new old
[–] n1729@lemmy.world 10 points 1 year ago

Interesting take from Nate.

I appreciate that he posted his perspective.

[–] ono@lemmy.ca 8 points 1 year ago (1 children)

One problem that has long plagued X11 is that any app can snoop on any other app, including things like keystrokes and displayed information, even from within containers like Flatpak. (This is understandable, since it was designed at a time when spyware was rare, so there was no need for isolation more fine-grained than the user level.)

IIRC, Wayland didn't address that problem in its early days, but in these modern times of surveillance capitalism, I suspect it has been getting more attention. It would be nice to see it solved.

[–] ExLisper@linux.community 11 points 1 year ago (1 children)

has long plagued X11

The risk existed but did it plague X11? I never heard about any app logging keystrokes and sending theme somewhere. Where there any attacks using this? I don't think normal uses had to worry about it.

[–] ono@lemmy.ca 6 points 1 year ago* (last edited 1 year ago) (2 children)

The risk existed but did it plague X11?

Yes, and it still does. Practically every X11 installation is vulnerable.

(If you're nitpicking my use of the word plagued, though, note that I am talking about the vulnerability, not the exploit.)

I never heard about any app logging keystrokes and sending theme somewhere.

That's because of a variety of external factors, including:

  • X11 desktops aren't common enough to be priority malware targets, yet.
  • People who run only open-source software typically get it from trustworthy channels, like their OS distro's package repository.
  • Devices likely to attract malware, such as game consoles and mobile phones, have avoided X11. (Android phones and Steam Deck are examples.) This is no accident; lack of app isolation was a factor in that decision.

I don’t think normal uses had to worry about it.

We've been lucky so far, in that our circumstances have kept us mostly safe. However, Linux malware is on the rise. Commercial games, both on their own and through anti-cheat systems, are making opaque software more common on our desktops. Flathub is working on paid apps, which could likewise create malware opportunities that weren't there before. The Epic Game Store has already been caught collecting data from other apps, so the intent is clearly present already.

It's generally just a matter of time before exploitable systems become exploited systems. We would do well to close the door on unauthorized key logging, clipboard snooping, screen scraping, and input injection.

[–] kugmo@sh.itjust.works -4 points 1 year ago (1 children)

This amount of security theater is why Wayland was unusable for 10 years

[–] semperverus@lemmy.world 3 points 1 year ago

Except it isn't theater, and you are not qualified to make that statement.

[–] solariplex@slrpnk.net 6 points 1 year ago (1 children)

Weird how this (and only this) link always opens in private browsing mode in Firefox Android / Fennec

[–] Triton@lemm.ee 8 points 1 year ago (1 children)

Are you using the Jerboa client? I think they recently introduced an option to open links in a private tab which is on by default for some reason. It confused me too until I found the setting.

[–] FarLine99@lemm.ee 2 points 1 year ago
[–] DarthSpot@feddit.de 2 points 1 year ago

I replaced my Nvidia with an AMD graphics card last year. Ever since ive been using Wayland on KDE Plasma without any issue. I have 2 VRR Monitors connected with different refresh rates, which felt clunky on X11 and now feels fluid and just brilliant to use. I don't use X11 Sessions at all anymore and only have XWayland for stuff that requires it