X11 has a way to avoid this in the form of untrusted clients. This feature has been neglected but if slightly adapted and used correctly, could complete avoid this issue. The reason it has been neglected is that all applications which run under the same uid can read each other's data anyway - so this kind of security never existed under Linux / UNIX (or other OSs) anyway, for reasons entirely unrelated to X. So activating it in X wouldn't really have helped.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
no subject
Date: 2016-04-22 11:35 am (UTC)