vaxry talked about
LD_PRELOADand I feel like that is a non-issue in this case.
If an attacker has the ability to modifyLD_PRELOADof an application, they already an ability to modify its behaviour without depending upon what D-Bus may let it do.
And if the attacker can changeLD_PRELOADfor a process running as root, they might as well affect the target service directly rather than try doing something with the dbus daemon.With each passing day Vaxry seems closer and closer to re-implementing the entire userland, I don’t know how he avoids burning out…
Hyperbola has been pointing out problems with dbus for years.
Portals could have been much simpler like how
xdg-openworks.I’m surprised it seems nobody has tried to write an alternative to portals that doesn’t use dbus?
Sounds good, good luck to the dev!