Hacker Newsnew | past | comments | ask | show | jobs | submit | more welterde's commentslogin

That's perfectly possible with X11 to attach via VNC to an existing session. But what X11 over (local) network does way better than either RDP or VNC is to run individual applications remotely while having them seamlessly integrate with the rest of desktop. At the observatory for example we were running thin clients in the control room while all the control panel windows were coming from many different machines across the mountain and it felt like all the applications were running locally on the machine in the control room (while in reality nothing was running there).


Yes, of course it is possible to use VNC with X11 as we use RDP with Windows. But it is additional protocol. Why do we need it if "X11 is network transparent"?

It is different models: X11 assume you have only one terminal (effectively client, but "server" in X11 parlance) and many system to run software (effectively servers, but "client" in X11 parlance).

VNC/RDP works other way around: one server, which runs all you programs, and you can attach to it from different terminals/clients.

It is not exactly so, as RDP can forward only some programs (windows) and not full screen, of course, but close enough.

I cannot speak for everybody, but for me (and my friends with whom I discussed this) second use case is much more important, than first one.

About speed: maybe, with 10Mbit Ethernet it was true. But now I could work with Photoshop (!) from my office (client) on my home workstation (server) via RDP and don't notice delays. Yes, I have 1000/100Mbit asymmetric connection at home and I don't know what is used by my office. One time I've forgot that it is RDP to my home sysmtem and started Youtube video. I was surprised, that video and sound is slightly off-sync, and only after that recognized that it is RDP, not local browser!

Much worse connection is enough for less demanding tasks, I've worked with "normal" not graphics-heavy programs via 4G connection in India (my home system is in the Netherlands) and it was not painful. Yes, there was perceivable delay, but for task like "Open PDF, open browser, fill form on site by copy-n-pasting strings from PDF, submitting form and authorize with 2FA from phone" it was perfectly Ok.

But, yes, if you need to assemble 10 windows from 10 remote machines on one screen, X11 is the best.


That is a bloody lie. Nothing on X feels like it's running locally except for actually locally running applications. String an Ethernet cable across the room, and run X apps remotely over it, and you'll get lag and chug.

RDP actually delivers on the promise of local-feeling remote apps.

(The revenge of the UNIX-HATERS is that Microsoft designed a better shell than sh (PowerShell), a better X than X (RDP), and a better Emacs than Emacs (Visual Studio Code).)


Maybe the problem was with your specific setup or applications? Because at the observatory it worked flawlessly. Between the local data reduction machine (beefy server) and the desktop computer in my office the same. And I used that setup for years and it worked just fine (and I really really hate any lag or glitches).

VNC really sucked on the other hand, not being able to transparently share single windows (at least I never figured out how to), some windows would fail to refresh and I would need to drag them around to get them to redraw, copy and paste was always a pain, sometimes inputs not registering properly.

To be fair to VNC though, over the internet plain X11 forwarding really sucked (latency is the real killer here) and VNC won out there. Unless one was using NX proxy, then it blew VNC out of the water (while using X11 on both ends). Only RDP was somewhat on par with NX over the internet, but locally still beaten by X11.


X11 with modern frameworks passes only damaged bitmaps too... No local font rendering, not vector primitives.

And for me inability to detach whole session from one server (in X11 terms) and attach to another is showstopper.

X11 needed something like console "screen"/"tmux" from the very beginning, in the core protocol, IMHO. Not for multiplexing of workspaces or desktops, but for this session re-attaching.


That is not true. There are extensions to the X11 server that can resolve many of the security issues, but almost no one cares enough to use them.

If you are doing X11 forwarding via SSH it defaults to a more restricted configuration that only allows a more restricted access to the server (no direct sniffing of the input devices for instance).


There seems to be XACE/XSELinux, which seemingly exists in the mainline Xorg distro now. I wonder how the experience is with that?

In practice I think it doesn't see any adoption, since most people don't run with SELinux or even AppArmor on their desktop and none of the applications run isolated from each other, so it doesn't matter that they all have full access to the X11 server. And for actual security there is qubes, which solves both the application isolation and the X11 security issue.


Eh even if you secure the X11 API itself, your isolated app (browsers absolutely sandbox and isolate themselves from the rest of the system) will still share memory and have a socket open to an 33 year old c codebase (XOrg).


Not sure having shared memory and socket open to N fresh and under active feature development c codebases is that much more conducive to security? (N since while many compositors use wlroots there is still enough rope to hang yourself). To be fair, unless there is a exploitable bug in wlroots/lower wayland code, the blast-radius will be a lot more limited than if one is found in Xserver.

I think the Qubes approach is the only one worth considering if one deeply cares about security.


Only for IPv4 destinations however, where there is no other way. For IPv6 destinations it's just native connectivity with no NAT.


Through a stateful firewall which blocks all incoming connections, completely invalidating "every device accessible" tenet of IPv6 and bringin zero value to the actual customers.


What do you mean it has never been tried? That's how a lot of mobile providers and home internet providers operate today. My provider in Germany was already using DS-Lite (native IPv6 and IPv4 is tunneled over IPv6 to CGNAT gateway) more than 8 years ago. Mobile phones often use 464XLAT where IPv4 is translated to a region of the address space within IPv6 (the backbone is IPv6-only).

The problem is the inverse direction (IPv4 -> IPv6) since IPv4 is lacking any mechanism for forward-compatibility.


That 22k limit is only for the small business rule, which allows the choice of not collecting VAT on sales (but on the flip side cannot deduct it on purchases). Up to a yearly revenue of 0.6M one can also use a simplified profit calculation method for taxes.


Ah yes, you're right. I'm still not that settled in on the rules... :-D


There are 2M sole proprietorships in Germany and around 0.4M partnership type companies (Personengesellschaft; GbR, etc.) and aside from the aspect of trying to appear like a large corporation while actually being a small start-up, they are perfectly adequate for many businesses.

There is also no limit on how large a sole proprietorship can grow. While mostly held up as example for why one might not want to keep the company form a sole proprietorship forever, Schlecker scaled from a single shop to over 14000 stores near the end and a couple billion euro revenue per year.


The relevant part is that they moved from another city to Munich, which means that certain company taxes would be paid in Munich instead of Unterschleißheim (the city where the HQ was located previously). This means a increase of tax revenue for the city of Munich of tens of MEUR/yr from this tax alone, without even considering secondary effects.

The small physical distance just means that this would be quite cheap for Microsoft to implement, compared to trying to pull the same stunt with another city.


Because it gets repeated on every thread on IPv6. IPv6 is perfectly backwards-compatible with IPv4 (you can run an IPv6-only host and still access hosts from the IPv4-internet). The issue however is that IPv4 is not forwards compatible. IPv4-only hosts cannot initiate communication with next gen protocol only hosts by design.


You more or less just reinvented a more complicated variant of 6to4/6rd, which is one of the IPv6 transition technologies.


Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: