• [^] # Re: Sécurité ?

    Posté par . En réponse à la dépêche Release Candidate 1 de XCB. Évalué à 5.

    Je cite Theo de Raadt:

    The X developers have created an X server which *REQUIRES* access the raw hardware.

    Therefore all the operating systems developers have given the X server such access, by creating a "hole" in their operating system, which permits the X server to access any chip-level registers it wants.

    This is called the "device drivers in userland" model. It violates all the security models you will hear of in a university class.


    They've had 10 years, and yet every year they get more entrenched in the entirely insecure model of "gigantic process running as root, which accesses registers like mad".

    This problem is ENTIRELY the X group's fault! They have failed us. Ten years ago they were laughing at Microsoft for moving their video subsystem into their kernel, but now the joke is on the X developers, because what Microsoft did solved all these driver security problems!

    This is 100% an X server bug. It is not a hardware bug, and it is not
    an operating system bug.


    Il y a quand même un (gros) problème avec le serveur X. Après, on est libre de l'appeller bug, problème de sécurité, ou "undocumented feature"...