Comment Re:Privilege escalation is to the server credentia (Score 1) 213
But, please tell me, which distro or OS do you run that runs your X11 server as non-root? Because I'd love to use a system like that.
It's possible on almost any Linux distribution if you're using a KMS-based (modern open-source) driver. Actually has been like that for a couple years now. There are some lingering permissions problems (need write access to the tty it's running on, a few other device nodes, and the log files -- most of these are solved by using SGID to a dedicated group rather than SUID to root, the rest require minor patches or config changes) but the big hurdles are gone.
It's not the default anywhere because it's mildly fiddly to setup and requires that you're using the open source Intel, ATI, or Nouveau drivers. Probably has some problems with using a display manager (KDM, GDM, XDM, etc.) too, as those login to the already-running X server rather than starting a new one for the user.