Secure attention key
Bug #237721 reported by
Fred
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
KDE Base |
Unknown
|
Wishlist
|
|||
Light Display Manager |
Won't Fix
|
Wishlist
|
Unassigned | ||
Unity System Compositor |
New
|
Undecided
|
Unassigned | ||
gdm |
Expired
|
Wishlist
|
|||
gdm (Ubuntu) |
Confirmed
|
Wishlist
|
Unassigned | ||
kdebase-workspace (Ubuntu) |
Won't Fix
|
Wishlist
|
Unassigned | ||
lightdm (Ubuntu) |
Won't Fix
|
Wishlist
|
Unassigned | ||
ubuntu-meta (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
unity-system-compositor (Ubuntu) |
New
|
Undecided
|
Unassigned | ||
xdm (Ubuntu) |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: gdm
In many environments computers are left unattended (e.g. schools, libraries, etc) and people can launch applications which mimic the look-and-feel of the login application (GDM) in order to get the users username and password.
This is called login spoofing.
* http://
Login spoofing can be prevented by using a secure attention key which is a key combination pressed before the user login to launch the password request dialog. This key can only be seen by the kernel, and not sniffed by any application.
* http://
Changed in gdm: | |
assignee: | nobody → desktop-bugs |
importance: | Undecided → Wishlist |
Changed in kdebase: | |
importance: | Undecided → Wishlist |
Changed in kdebase: | |
importance: | Undecided → Unknown |
status: | New → Unknown |
status: | New → Triaged |
Changed in kdebase: | |
status: | Unknown → Confirmed |
tags: | added: login security |
security vulnerability: | no → yes |
security vulnerability: | yes → no |
Changed in kdebase: | |
importance: | Unknown → Wishlist |
Changed in gdm (Ubuntu): | |
assignee: | Ubuntu Desktop Bugs (desktop-bugs) → nobody |
Changed in gdm: | |
importance: | Unknown → Wishlist |
status: | Unknown → New |
Changed in gdm (Ubuntu): | |
status: | New → Confirmed |
Changed in lightdm: | |
status: | New → Triaged |
importance: | Undecided → Wishlist |
Changed in lightdm (Ubuntu): | |
status: | New → Triaged |
importance: | Undecided → Wishlist |
Changed in kde-baseapps: | |
status: | Confirmed → Unknown |
Changed in gdm: | |
status: | New → Expired |
To post a comment you must log in.
Sounds reasonable :-)