Screen Locking Problems

Matthew Miller mattdm at mattdm.org
Thu Mar 3 03:03:28 UTC 2005


On Wed, Mar 02, 2005 at 04:23:37PM -0500, David Curry wrote:
> back to init level 3.  If the user's username and password are known to 
> someone else, that someone else could easily kill the X session and log 
> back in to X.org as the party who set the screenlock.  In addition, 

Errr, if they know the username and password, they could just unlock the
screensaver, with no need to kill the session.

> Screensaver -> Help - > Frequently Asked questions -> #22 points out 
> that if the user is logged into a non-X console session, Ctl-Alt-F1 on 
> the keyboard will switch the screen to that non-X console.

And again require a login. If you want to disable this (for a kiosk, say),
set the DontVTSwitch option to true. (You can also set DontZap, to disable
Ctrl-Alt-Backspace, if you want.)

> I haven't really explored either one of the things suggested by the faq, 
> but it seems to me that screen lock has real weaknesses as an overnight 
> security measure.

It might, but I don't see how it's the things you've listed.


-- 
Matthew Miller           mattdm at mattdm.org        <http://www.mattdm.org/>
Boston University Linux      ------>                <http://linux.bu.edu/>




More information about the fedora-list mailing list