Hacker News new | ask | show | jobs
by akimbostrawman 507 days ago
>Any process you run can already access the memory and files of everything else as the same user.

*When the applications themselves aren't properly sandboxed. If they are with for example firejail, flatpak or snap. Then x11 is a gaping hole like having proper doors in a house but broken windows.

It's not the job of the compositor to sandbox applications.