Re: Unauthenticated user can modify the background in a widget-lock-screen

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




Am 16.03.2013 23:21, schrieb Kevin Kofler:
> Gilboa Davara wrote:
>> While testing 4.10/f17 I decided to try out the new lock screen.
>> The widget lock screen is indeed nice, but there's a major security issue:
>> An unauthenticated user can access the lock-screen setting and change the
>> background. (cashew->settings).
> 
> Changing the background is a "major security issue"?!

without testing it personally:

it can get easily become one if you can open a file-dialog
in special cirumstances - so to be safe the only allowed
action in the lockscreen should be enter the password

look at the news of the last few months from Samsung and
Apple Smartphones to bypass the lockscreen, that is what
i mean with "special cirumstances"

there where so many tricky exploits which left my mouth
open with a "uhm how comes someone to THAT idea" that
i started to get very paramoid if it comes to security


Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
kde mailing list
kde@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/kde
New to KDE4? - get help from http://userbase.kde.org

[Index of Archives]     [KDE Users]     [Fedora General Discussion]     [Older Fedora Users Mail]     [Fedora Advisory Board]     [Fedora Security]     [Fedora Maintainers]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [ATA RAID]     [Fedora Marketing]     [Fedora Mentors]     [Fedora Package Announce]     [Fedora Package Review]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Triage]     [Coolkey]     [Yum Users]     [Yosemite Forum]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]

  Powered by Linux