Circumventing Ubuntu Snap confinement
mjg59.dreamwidth.org
mjg59.dreamwidth.org
In college I spent a bit of time trying to write what's effectively a NATing proxy for the X protocol: clients get their own XIDs in their own namespace, and can't refer to other clients' resources. They see a virtual root window that only has their own windows. If X is going to stick around and people are going to attempt to care about security, it'd be worth implementing something like that.
http://www.x.org/releases/X11R7.5/doc/security/XACE-Spec.htm...
https://insights.ubuntu.com/2016/04/20/canonical-unveils-6th...
http://www.x.org/wiki/Development/Documentation/Security/ is one.
Another is to run each program inside their own "server", via xnest, xephyr or similar.