[Bug 82052] possible security issue with locked screen
ethrandil
ethrandil at gmx.net
Sun Jan 28 23:29:13 UTC 2007
Public bug reported:
Hello,
my family uses a nice feature: After 45 mins of not moving the mouse the
screen locks and if another person wants to login he could login himself
in a parallel session.
The problem is that my password could be exploited! Following stragegy:
1. Person A loggs in and locks the Computer
2. Person B loggs in himself and prepares an identical looking screen
3. Person A comes back fills in his password - BANG - [B knows As password]
3b. Person B could add functionality to his prepared screen to log in A.
Well, this is not too dangerous in our house, but I think it is in a company. Maybe that feature shouldn't be available without warning.
Just wanted to report that.
- eth
** Affects: gnome-screensaver (Ubuntu)
Importance: Undecided
Status: Unconfirmed
--
possible security issue with locked screen
https://launchpad.net/bugs/82052
More information about the desktop-bugs
mailing list