Gentoo Archives: gentoo-user

From: Rich Freeman <rich0@g.o>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] from Firefox52: NO pure ALSA?, WAS: Firefox 49.0 & Youtube... Audio: No
Date: Fri, 16 Dec 2016 13:35:47
Message-Id: CAGfcS_=LvKf+pbq1Pfs_RfNUB76yFHz3Dv-FK0ZdFAMt_mAbYQ@mail.gmail.com
In Reply to: Re: [gentoo-user] from Firefox52: NO pure ALSA?, WAS: Firefox 49.0 & Youtube... Audio: No by Miroslav Rovis
1 On Fri, Dec 16, 2016 at 8:13 AM, Miroslav Rovis
2 <miro.rovis@××××××××××××××.hr> wrote:
3 > On 161216-07:16-0500, Rich Freeman wrote:
4 >> On Fri, Dec 16, 2016 at 5:19 AM, Miroslav Rovis
5 >> <miro.rovis@××××××××××××××.hr> wrote:
6 >> >
7 >> > In my stron opinion, and opinions are allowed in Gentoo, just not
8 >> > imposing your opinion onto others (and that I am not doing, feel free
9 >> > to disagree!), pulseadio is spyware, read more here:
10 >> >
11 >> > Re: [Alsa-user] sans-pulseaudio Firefox? was: a strange thing
12 >> > https://www.mail-archive.com/alsa-user@×××××××××××××××××.net/msg31928.html
13 >> >
14 >>
15 >> What exactly about Pulseaudio do you think makes it "spyware?" The
16 > You're right actually. Or might be. It is likely not spyware in itself,
17 > but it surely is spyware enabler. Like dbus and all of poetterware.
18 >
19 > And about xorg. Everybody uses it, I do too. Minimalistically. Just
20 > enough to have, say Firefox and Wireshark, and a good *nix programs that
21 > need gui. But I'd think the possibilities for spying-required remote
22 > connections with xorg are nowhere near to what poetterware and
23 > associates offer.
24 >
25
26 I'm not sure I understand what distinction you're making. I can't say
27 I'm intimately familiar with the security model around Pulseaudio (at
28 a glance it seems similar to X11 with its use of cookies, though
29 obviously if you tell it to broadcast unencrypted multicast RTP on
30 your LAN you'll get the obvious effects) but X11 has a couple of
31 glaring security weaknesses. The most obvious is the fact that any
32 random X11 client can read the keyboard input of any other client on
33 the same server unless you jump through a bunch of hoops that I don't
34 think anybody actually jumps through (though I do believe some of the
35 X11 PIN entry programs may use them at least). Anything you type into
36 an xterm could be read by your browser, and in turn by any code able
37 to execute outside any sandbox that browser might have (root privs not
38 needed for this).
39
40 And I wouldn't be surprised if a lot of X servers still run as root
41 for modesetting/etc.
42
43 > That's why they came into existance, after all.
44
45 Uh, somehow I doubt that Lennart wrote Pulseaudio just to simplify the
46 task of getting audio off of a local host so that somebody can spy on
47 you. Maybe it had something to do with the fact that before it came
48 along just doing something like plugging a USB headset into a Linux
49 desktop was a bit of a chore?
50
51 Well, if you prefer not to use Pulse, that's of course up to you. I
52 wasn't running it for ages, and I probably still wouldn't be running
53 it if I didn't have issues with running multiple desktop sessions as
54 separate users (one of those things that stuff like pulse+policykit
55 and so on was designed to help fix).
56
57 --
58 Rich

Replies

Subject Author
Re: [gentoo-user] from Firefox52: NO pure ALSA?, WAS: Firefox 49.0 & Youtube... Audio: No Miroslav Rovis <miro.rovis@××××××××××××××.hr>