Hacker News new | ask | show | jobs
by vbernat 2965 days ago
Xauthority isn't fine-grained. Once you get a cookie, you haven't any restriction to what you can do with the X server.
1 comments

We could generate an "untrusted" cookie. This prevents clients using it from meddling with "trusted" clients.

It's not really fine grained and also doesn't prevent untrusted clients from meddling with one another, but seems like a starting point for someone inclined to add more security to X.