I have no opposition to Wayland in theory; my concerns are entirely practical and unignorable.
I think your argument is about specific implementations of WM. While the argument of "I deal with X11-based WMs because it's fine when I don't care about security at all" may be valid in very narrow cases (such as air-gapped systems), the argument more generally is pretty weak.
Its not surpising that x11 based WMs, such as the almighty [awesomeWM](https://github.com/awesomeWM/awesome), have more features implemented than, for instance, [jay](https://github.com/mahkoh/jay) due to the enormous time it has had to develop (though I am _very_ excited to see `jay` develop more fully, and expect it to be well used by the more tech-savy devs).
However, some WMs in the Wayland space are doing quite well on that front. I recently had some substantial problems arise in my system which (surprisingly to me, but perhaps some are getting used to this) would have been prevented by using a memory safety language for my WM, so I have made the switch to (for better or worse) only ever consider Wayland+Rust WMs. In this space, [niri](https://github.com/YaLTeR/niri) is actually quite good, and to the point - it is developing correctly _and very quickly_. So, any issues on some WM not implementing some desired feature are quickly disappearing.
IIRC, all the major 'gateway' linux distros, such as Ubuntu or Fedora, are all on Wayland by default now - so I don't imagine x11 will stay relevant much longer.
This is not something you should ever have to do
Then nVidia decided to switch to GBM/EGL way of doing things and it turned out everyone had incorrect assumptions...
The ecosystem slowly moves towards explicit sync now, but Nvidia was supposed to provide a driver already before that was happening and they didn't comply with platform's requirements at date, resulting in user-facing issues. With this one, they just got lucky that the consensus happens to move towards what they had already asserted.
It depends on the type of jank you're talking about. It's wholly disingenuous to characterize Wayland as janky but x11 as not - the jank inherent to x11 is what made the original Xorg developers start making Wayland in the first place. Empirically, if x11 was perfectly fine there would be no motivation to design a successor.
x11 gets the first-mover advantage of a lot of implementations and a straightforward design goal, but that's about it. It's not secure enough to recommend as a serious alternative to Mac and Windows users, and it's too slow and unopinionated to present a friendly face to new users. Features like 1:1 trackpad gestures, genuine HDR pipelines and a locked compositor framerate are all getting to the point that regular consumers expect them as default.
If you want to keep using x11, it's unlikely someone is going to take it away from you. But it's on track for depreciation and hasn't been actively developed in years. Recommending it as a panacea to new users is a bad idea.
The security risk of X11 is theoretical, not practical. Yes, X11 programs can maliciously keylog each other, but this just isn't a thing that actually happens. And even if you do start installing random malware from the internet like a classic windows user, Wayland isn't going to prevent you from screwing yourself anyway. To actually be safe while installing and running malicious applications you need extensive sandboxing. Wayland can be one part of that sandboxing but is useless without the rest (to prevent the malware from stealing user files including credentials, using LD_PRELOAD hacks or similar to keylog other applications anyway, etc), and no distro suitable for recommending to Windows/MacOS newbs has the rest of the requisite sandboxing. The sandboxing touted by Wayland advocates is very esoteric and without all that sandboxing, a newb using Wayland has to exercise just as much caution when downloading software as if he were using X11.
Are you really saying keyloggers do not exist in the wild???
> Wayland can be one part of that sandboxing but is useless without the rest
Yes but that is the point, and if you turn it the other way around X11 usually makes the rest of the sandboxing useless.
And yes, X11 makes that sandboxing useless, but that sandboxing isn't in play anyway because we're talking about noobs from Windows.
In principle I am also vulnerable to something like a RCE zero day in Firefox turning an otherwise trusty program into malware which exploits X11's open nature, but again, this sort of thing actually happening is unheard of.
I'm not superior, I'm just trying to keep a realistic grip on the threats I face. Modern security culture is fixated on what is theoretically possible, I care more about what is actually likely.
I disagree. How do you hijack interprocess communication on a Wayland device? I can tell you in very certain steps how to manipulate an x11 client but outside hijacking /dev/ I can't imagine a similar attack on Wayland.
A simple search leads me to this: https://github.com/anko/xkbcat
There isn't a real attack using it yet, only because attacking Desktop Linux is a really unprofitable endeavor (considering the marketshare, the ROI must be very low).
> To actually be safe while installing and running malicious applications you need extensive sandboxing
FWIW, X11 is unsandboxable unless you run a second X server on top of your current server [0]. Which is fine, but you need to consider that most, if not all sandboxing solutions on Linux that "newbs" use, like Flatpak, do not employ such technique when running sandboxed X11 applications.
The "security by default" behavior of Wayland limits the possible attack surface a lot, without requiring the end user to understand all the nitty details involved.
[0]: https://wiki.archlinux.org/title/Bubblewrap#Sandboxing_X11
When this is the case and there is a supply chain attack, what you think is a trusted application (and therefore not running under "WaylandX") can very well keylog you or take screenshots of your desktop without your consent.
In a deny-by-default model ala Wayland, applications will have to ask for permissions before they can do something considered to be privileged.
This cannot be more further from the truth. Amongst the newcomers, it is rather popular nowadays for them to use Flatpak-bundled apps, especially with the rise of SteamOS (the Deck essentially) lots of Linux newcomers are in fact first exposed to Flatpak and running untrusted executables in a sandbox.
And the most prominent "untrusted executable" today to those newcomers has to be Bottles, which is a nice GUI wrapper for Wine and is sandboxed (if you enable wine-wayland, of course).
But I don't think a game purchased through steam counts as untrusted.
As compared to running untrusted programs completely naked?
>But I don't think a game purchased through steam counts as untrusted.
Bottles is there for people to run any Win32 program, not just Steam games. And I shouldn't have to tell you how many malicious Win32 programs there are.
Containerization on Linux was never intended to be a security feature for totally untrusted, malicious code. It's isolation for trusted code. If your scenario relies on securely running untrusted executables in a Linux container you are doing stupid things.
You see: If you want absolute security, for sure, go for a full-fledged VM! Or run something like QubesOS. It is a completely reasonable decision.
However, malice certainly has degrees, and the "mildly malicious" programs most likely cannot take advantage of sandbox escaping exploits. If Flatpak can stop 95% of all attacks (relative to running a program completely without sandboxing), that is already a win in my book.
But I will note again that X11 is a big hole (as in, almost a complete free-for-all) for sandbox escaping in Flatpak.
I'm done with this thread, have a nice day.
And besides that, "these threats are off in fantasy land" is an invalid defense in my opinion, considering the (quite sophisticated) XZ Utils backdoor happened not too long ago! Like I said, if such an attack towards X11 hasn't been deployed in the wild, it can only suggest such endeavor is unprofitable, not because the threats are fantastical.
If the attacker decided to backdoor an utility and make use of X11, it is most likely the backdoored utility will listen to keyboard events, read the bitmaps of other X11 clients.
And there's nothing that can stop the backdoor from doing so on X11...
Anyways, if you are saying the Wayland security policies are unneeded because there hasn't been an attack on X11 (this is the fundamental disagreement between us), consider the following: You don't install doors in your premise, because there hasn't been a case of burglary in your neighborhood?
I've been recommending it as a serious alternative for years, and it's always presented a friendly face.
> Features like 1:1 trackpad gestures, genuine HDR pipelines and a locked compositor framerate are all getting to the point that regular consumers expect them as default.
I have never heard anyone not already a Linux user comment on even one of those as a problem.
Those specific words are uttered by Linux users, true. However, Linux beginners _do_ notice some X11 issues, it's just that very frequently they only know "something" is off but not why they feel so.
From anecdotal experience, touchpad gestures are actually something my friend complained so YMMV. We ended up making a file in /etc/X11/xorg.conf.d/ to configure the synaptics driver. Another experience had to do with screen tearing, I helped them fix it by installing a compositor.
....because Windows and Mac users have not had these problems since 2006?