[Bug 474654] Re: [SecurityRoadmap] Desktop visible when screen is locked in Kubuntu

Bug Watch Updater 474654 at bugs.launchpad.net
Sat Jun 30 20:56:55 UTC 2012


Launchpad has imported 9 comments from the remote bug at
https://bugs.kde.org/show_bug.cgi?id=246623.

If you reply to an imported comment from within Launchpad, your comment
will be sent to the remote bug automatically. Read more about
Launchpad's inter-bugtracker facilities at
https://help.launchpad.net/InterBugTracking.

------------------------------------------------------------------------
On 2010-08-03T17:57:45+00:00 art alexion wrote:

Version:           0.2 (using KDE 4.4.2) 
OS:                Linux

This is a security setting.  The expected behavior is that an
unauthorized person will not be able to view the desktop if the password
isn't entered.  With the current behavior, the desktop is revealed;
interaction is prevented, but private information open is revealed.

Reproducible: Always

Steps to Reproduce:
Go to system settings>Desktop>Screen Saver.  Activate the screensaver.  Check the box "Require password to stop".  Activate screen saver.  move mouse or tap keyboard to stop screensaver.  Desktop is revealed, and password entry box becomes modal over the system.

This happens with blank screen screensaver.  Others not tested.

Actual Results:  
The behavior revealing the screen, even before the password is entered, makes this of limited security value.

Expected Results:  
That some other visual obscures the screen.  For example, Gnome continues to show only a blank screen and the password entry dialog.  Windows shows some variation of the login screen. 

OS: Linux (x86_64) release 2.6.32-24-generic
Compiler: cc

I think this is a security bug.

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/12

------------------------------------------------------------------------
On 2010-10-23T23:47:42+00:00 Oswald Buddenhagen wrote:

i think bug 183496 comment 8 describes the same problem. like bug 183496
itself, it is possibly also related to compositing (please try disabling
it and report back), but is a different issue as such (x server/driver
bugs have been suggested - what graphics card + driver are you using?).

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/15

------------------------------------------------------------------------
On 2010-10-23T23:49:52+00:00 Oswald Buddenhagen wrote:

*** Bug 249417 has been marked as a duplicate of this bug. ***

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/16

------------------------------------------------------------------------
On 2010-10-24T01:13:25+00:00 art alexion wrote:

I upgraded to Kubuntu 10.10 and no longer see this behavior.

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/17

------------------------------------------------------------------------
On 2011-04-16T15:44:11+00:00 Maarten Bezemer wrote:

I can confirm this behavior.
I happens frequently (not always), I do not know what triggers this behavior...

When I leave my office at work I just the lid of my laptop in order to
lock the session, Sometimes when I come back I can see my entire desktop
before logging into the locked session.

Running Kubuntu 10.10 / KDE 5.4.1
Using an ATI video card with fglrx package version 2:8.780

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/19

------------------------------------------------------------------------
On 2011-04-16T15:46:43+00:00 Maarten Bezemer wrote:

LP #474654 https://bugs.launchpad.net/kdebase/+bug/474654

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/20

------------------------------------------------------------------------
On 2011-06-02T16:32:20+00:00 Oswald Buddenhagen wrote:

*** Bug 270957 has been marked as a duplicate of this bug. ***

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/21

------------------------------------------------------------------------
On 2012-01-06T12:40:42+00:00 art alexion wrote:

There seems to be a regression with Kubuntu 11.10/KDE 4.7

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/23

------------------------------------------------------------------------
On 2012-06-30T20:53:28+00:00 Kevin-kofler wrote:

Also reported in Fedora as
https://bugzilla.redhat.com/show_bug.cgi?id=677345 .

Reply at: https://bugs.launchpad.net/kde-
baseapps/+bug/474654/comments/24


** Bug watch added: Red Hat Bugzilla #677345
   https://bugzilla.redhat.com/show_bug.cgi?id=677345

-- 
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to kdebase-workspace in Ubuntu.
https://bugs.launchpad.net/bugs/474654

Title:
  [SecurityRoadmap] Desktop visible when screen is locked in Kubuntu

To manage notifications about this bug go to:
https://bugs.launchpad.net/kde-baseapps/+bug/474654/+subscriptions




More information about the kubuntu-bugs mailing list