Did Hyprland Ship A Major Plugin Vulnerability?

Did Hyprland Ship A Major Plugin Vulnerability?

#Hyprland #Ship #Major #Plugin #Vulnerability

“Brodie Robertson”

Hyprland is back in the news once again because of a “vulnerability” but is it really as bad as it’s made out to be or is it being a little overblown

 

To see the full content, share this page by clicking one of the buttons below

==========Support The Channel==========
► Patreon:
► Paypal:
►…

source
Concluzion: Did Hyprland Ship A Major Plugin Vulnerability? – brodie robertson,hyprland,brodie robertson linux,brodie robertson hyprland,brodie robertson arch linux,arch linux,linux desktop,open source,foss,the linux experiment,distrotube,chris titus tech,hyprland plugin,hyprland linux,linux,hyprland rice,hyprland arch,hyprland arch linux,linux news,tech news,hyprland vs sway,sway vs hyprland,best linux desktop,best linux desktop 2024,x11,x11 vs wayland,wayland,wayland vs x11,xorg,linux tutorial

source

About danroo

Check Also

Como medir la calidad del código

Como medir la calidad del código #Como #medir #calidad #del #código   To see the …

29 comments

  1. I don't see the issue with Vaxxrys reaction if you consider how the issue was reported and that he fixed it immediately. What this looks like to me is that there are people who due to the recent drama decided to bully the Hyprland project.

  2. blank

    No thanks, Hyprland seems doomed to fail because there is entirely too much immature drama & cumulative bloat every release.
    SwayFX all the way without all that, devs just released a new version too.

  3. blank

    Oh that's why i earned a new environment variable to the socket… Anyway

  4. blank

    I know very little about Hyprland and it's creators, but I keep hearing about problems with it's creators/maintainers. – And what I took from this video was: other developers dislike this guy to a degree where they would rather ignore and/or publish security vulnerabilities rather than deal with him. – This sounds… problematic for the project.

  5. blank

    Too be fair there are a lot of script kiddies who would rather run some random install script off of github than RTFM, and seeing them get pwned would be kinda funny

  6. blank

    Coding in swift while watching a video about major bugs in assembly getting fixed within hours has never ruined my confidence more. Keep it up Brodie!

  7. blank

    Nobody talking about the fact that this hook system is completely overengineered?

  8. blank

    "powerful" and "plugins" are a bad combo

    (And also just a terrible design. No clear API is just asking for breakage and unintended dependencies between basically everything. C++, OOP and especially mixing it with all the low-level knobs and levers were a mistake.)

  9. blank

    CVE-Brodie-2024: Brodie didn't want to turn the light on

  10. blank

    4:42 Well, he's a programmer, I guess.

  11. blank

    I host things on my PC and also have a couple of users for my friends and for my work. I have tried hyprland and still have it installed. I guess I'd just have to install a random plugin and switch to hyprland for me to be a perfect target.

  12. blank

    Putting innocent users at risk because you don't like the developer is detestable.

  13. blank

    A practical demonstration of how having toxic developers/community does affect software quality.

  14. blank

    is it just me or trampoline shouldnt be used in this case anyway

  15. blank

    tbh i love vax and i don't think he should change

  16. blank

    You gotta do some shit for people not prioritizing reporting upstream to you. Holy hell.

  17. blank

    You forgot the most important thing which is that hyprland uses XDG_RUNTIME_DIR/hypr instead of /tmp/hypr for everything now which should have been the obvious choice from the start and easily prevents any problem like this from ever happening.

  18. blank

    For multiple user you need friends. On linux thats a low risk cve.

  19. blank

    "I cannot report a vulnerability because the mean man said a naughty word" You are pathetic and will never make it in the real world.

  20. blank

    ngl the initial reporter had this aura of "holier than thou" mentality which even reads really offputting. If he really didn't care, then why make that email post. Just for the credits and the clout?
    just sounds miserable to be around, tbh.

  21. blank

    what vulnerability? correct me if I’m wrong, but if you’re running a hyprland plugin, you’re already putting your system at risk because you might not know what code you’re actually running

    a GitHub issue should’ve been made first imo

    edit – should’ve probably watch a little more

  22. blank

    i do disagree that it's not that important a vuln. a service could be compromised, and constrained within a low privilege service user. this would have provided a way out of that, probably to a user with the wheel group. this is the start of a route to root. raising it is right, surely.

  23. blank

    nah, part of FS should be to have fun

  24. blank

    Laughing at someone who writes about a potential vulnerability is a no-go. And if you do and then you find out you were wrong, that’s a big cause to say you’re sorry. And “you disrespect the user” followed by “if you [vulnerable user] exist” is kind of a bad take. If this wasn’t relevant to anyone, then no one was disrespected. And if it was, then vulnerable users exist. ⇒ less defensive, please. I get from this video why the reporter did not write to upstream but rather wrote about it in a roundabout way (don’t want to make it too clear, lest people exploit it) to enable others to report it.

Leave a Reply