Dash can be activated while screen is locked

Bug #946888 reported by Jeet
286
This bug affects 7 people
Affects Status Importance Assigned to Milestone
unity-2d
Invalid
Undecided
Unassigned
compiz (Ubuntu)
Invalid
High
Canonical Desktop Experience Team
Precise
Invalid
High
Canonical Desktop Experience Team

Bug Description

What happens:
Screen lock: prior to login the system responds to the first several characters typed and responds to mouse or trackpad movements.

For security sake; Shouldn't this be tightened up?

What should not happen:
Input buffer should not accept signals (ie: characters, keyboard strokes; and not mouse or trackball inputs.

What could potentially happen:
the Hack of system by way of buffer use; thru the momentary laspe of security during the first instance of "locked screen" activity just prior to a login.

Try it and you'll see.

Let me know what your thoughts are:

cliffcarusa at gmail dot com

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Steps to reproduce:

1- Lock screen with Ctrl-L or indicator menu
2- type random password
3- While password is being checked, press meta key
4- use correct password
5- Notice the dash is open, which means the meta key is being grabbed while the screensaver is active

I haven't been able to type anything, but others have successfully managed to type stuff into the dash

affects: ubuntu-meta (Ubuntu) → compiz (Ubuntu)
Changed in compiz (Ubuntu):
status: New → Confirmed
security vulnerability: no → yes
summary: - Loose security on Locked screen.
+ Dash can be activated while screen is locked
Changed in compiz (Ubuntu Precise):
milestone: none → ubuntu-12.04-beta-2
tags: added: rls-p-tracking
Changed in compiz (Ubuntu Precise):
assignee: nobody → Canonical Desktop Experience Team (canonical-dx-team)
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

I think this is the same issue as bug 806255, which I was going to look at this week.

Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Actually, I'm not convinced this is a duplicate of bug 806255.

Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Though this bug may be directly related to bug 917477.

Changed in compiz (Ubuntu Precise):
importance: Undecided → High
tags: added: rls-mgr-p-tracking
Revision history for this message
Martin Pitt (pitti) wrote :

I'm not able to reproduce this in Unity 5.8, is anyone else able to?

Changed in compiz (Ubuntu Precise):
milestone: ubuntu-12.04-beta-2 → ubuntu-12.04
Revision history for this message
Andrea Azzarone (azzar1) wrote :

I'm not able to reproduce this bug here.

Tim Penhey (thumper)
Changed in unity:
status: New → Triaged
importance: Undecided → High
assignee: nobody → Gord Allott (gordallott)
milestone: none → 5.10.0
Revision history for this message
Gord Allott (gordallott) wrote :

Seems to not be an issue anymore, will close if no one can reproduce

Revision history for this message
MikhailValerie (mikhailvalerie) wrote :

I am able to reproduce this in Unity 2D (up-to-date so I'd be using 5.8). I have not tried with Unity 3D (compiz) yet.

I can only seem to get the [META]/[SUPER] key to work by itself and not any other combinations (like [META]+1 (Marlin), [META] + S (workspaces) or [ALT] + [TAB]), nor can I get letters into the dash search field.

Would my issue be considered this bug, or a similar one (seeing as this one is tagged with compiz)? It could also be related to bug #806255.

Revision history for this message
MikhailValerie (mikhailvalerie) wrote :

I tried to reproduce in Unity 3D (compiz) but could not.

Perhaps this bug should be considered closed and a new one filed for my issue with Unity 2D (unless there is already one I haven't found yet - will keep looking).

Revision history for this message
Tim Penhey (thumper) wrote :

I tried to reproduce in 3d, but couldn't. Reassigning to 2d.

Changed in unity:
milestone: 5.10.0 → none
assignee: Gord Allott (gordallott) → nobody
importance: High → Undecided
status: Triaged → New
affects: unity → unity-2d
Changed in compiz (Ubuntu Precise):
status: Confirmed → Invalid
Revision history for this message
Michał Sawicz (saviq) wrote :

I can confirm this is happening, it's like that because of how we listen for modifier events. Should probably find out if the screen is locked and ignore them in that case.

Changed in unity-2d:
status: New → Confirmed
Revision history for this message
cliffcarusa (cliffcarusa) wrote : Re: [Bug 946888] Re: Dash can be activated while screen is locked

Thank you one and all for your consideration and research on this issue.
Currently it continues to occur with ubuntu 12.04 LTS installation.
Cliff.

On Fri, Mar 30, 2012 at 2:52 AM, Michał Sawicz
<email address hidden>wrote:

> I can confirm this is happening, it's like that because of how we listen
> for modifier events. Should probably find out if the screen is locked
> and ignore them in that case.
>
> ** Changed in: unity-2d
> Status: New => Confirmed
>
> --
> You received this bug notification because you are subscribed to the bug
> report.
> https://bugs.launchpad.net/bugs/946888
>
> Title:
> Dash can be activated while screen is locked
>
> Status in Unity 2D:
> Confirmed
> Status in “compiz” package in Ubuntu:
> Invalid
> Status in “compiz” source package in Precise:
> Invalid
>
> Bug description:
> What happens:
> Screen lock: prior to login the system responds to the first several
> characters typed and responds to mouse or trackpad movements.
>
> For security sake; Shouldn't this be tightened up?
>
> What should not happen:
> Input buffer should not accept signals (ie: characters, keyboard
> strokes; and not mouse or trackball inputs.
>
> What could potentially happen:
> the Hack of system by way of buffer use; thru the momentary laspe of
> security during the first instance of "locked screen" activity just prior
> to a login.
>
> Try it and you'll see.
>
> Let me know what your thoughts are:
>
> cliffcarusa at gmail dot com
>
> To manage notifications about this bug go to:
> https://bugs.launchpad.net/unity-2d/+bug/946888/+subscriptions
>

Changed in unity-2d:
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Related questions

Remote bug watches

Bug watches keep track of this bug in other bug trackers.