|
|
|
|
|
by hpfr
1986 days ago
|
|
Yes, they fixed the bug, which is good, but if you read jwz’s post, the issue is that these bugs don’t fail safe. A screen locker shouldn’t crash to an unlocked session. The design of a screen locker should take into account that bugs and crashes will exist and strongly prioritize failing safely. |
|
> But if xscreensaver crashes, the screen is unlocked, and our attacker is now logged in as the person who locked their screen.
EDIT: To clarify I meant that jwz' blog post is the one which implies otherwise.