It seem that the same people that believe we need to secure our display server against malicious clients almost inevitably want some sort google play store like experience where people release software for linux in some sort of universal way wherein distros would have no input rather than repo concept that is traditional now.
I feel like they haven't thought this through and will leave us on net substantially less secure.
I'm not sure exactly how X works here. I think as long as you have a visible window (1x1 pixel or more), you can get all keyboard input.
This may or may not be central to your point, but I wanted to have it out there to better inform about how Wayland improves upon X :)
http://security.stackexchange.com/questions/119410/why-shoul...
Admittedly I haven't studied this in detail, so maybe there are some fatal aspects in Wayland that would make my ideas infeasible, but I hope that one day we could have more secure desktop privilege authorization.
Not knowing exactly what Text Expander is, I'm guessing it would probably need access to a specific protocol for controlling accessibility features. The Wayland server would need to be configured to allow this app access to that protocol somehow, for example by way of a server-initiated popup window that asks you to allow or deny this access.
Does that explain it?
Nor should it. That kind of sandboxing should be done as a wrapper around a particular program, not in the display server. A nested X server that sanitizes the protocol wouldn't be particularly difficult. Also, if your aren't fully sandboxing your potentially hostile application, a keylogger is the least of your problems. The display server isn't going to protect you from actual local attacks and privilege escalations; instead, it will only provide a false sense of security.
Furthermore, doing this in the display server itself is shortsighted and unfortunately typical of the freedesktop.org development style that refuses to consider use cases outside their limited personal experience. I use the ability to send synthetic keyboard and mouse events to arbitrary X clients regularly. Occasionally I use the ability to keylog to work around poorly written software. If Wayland refuses to support these features, it isn't compatible with my software.
Security is important, but simply removing features isn't the solution. Gnome/KDE may be popular, but many of us have software that uses X directly. Some of it written before those "desktop environments" even existed.
Nested X servers are a pain, if you've used one - the things you're used to, like functional copy/paste, performant operation, tend to disappear and make this a non-workable solution.
Furthermore, if you look at the release not of (e.g.) firejail, a wrapper around a local program, you'll notice that indeed a lot of the revisions are trying to avoid X bugs that let applications act as key-loggers etc. People have tried, and it turns out to be difficult.