Live data from Hacker News

macOS lock screen: “I just sent my session pass to my whole team”

twitter.com

41–50 of 276 posts

Re: macOS lock screen: “I just sent my session pass to my whole team”

#41
post #36

I may be wrong, but Slack might be hijacking the window order, there's def some monkey business going on there.

Nothing should be able to hack outside of of the lock screen. That should require some crazy special permissions.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#42
post #30

Lock screens are harder than they first appear: www.jwz.org/xscreensaver/toolkits.html (Which, you'll note, mentions this exact failure case in the "Transfer Grabs?" section.) There's some X-specific stuff in there, but there's a lot of general issues in there, and with just a bit of imagination most or all of the X-specific issues can be seen as general issues as well.

Fair warning: Jamie doesn't appreciate the discourse this crowd brings to his site. Visit this URL without a referrer for the best results.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#45

I worked at an open source shop where almost everyone ran Linux and used IRC for chat. For a while I made the mistake of having the screen black time lower than the screensaver timeout, so I'd unlock my screen and see my password go out in IRC. I ended up changing my password to something that looked like a shell command.

I worked in a mixed shop, and when my Linux box showed the BSOD screensaver, my Windows-aligned co-worker helpfully rebooted my machine for me.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#46
on .2 already. Never had an unwatch to unlock. The ghost typing happened to me yesterday. I never found out what got my password. hopefully it wasn't slack. I assumed it just went to the "root window" (does quartz have the same concepts as X?) of the lock screen

I usually press control key to wake up every computer (shift doesnt work on some). that one time I woke it up by tapping on the touchpad.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#47
post #44

Apple has a bug bounty program where they'll legitimately pay you to report bugs directly to them. What's with everyone reporting them to Twitter instead and forgoing the extra cash?

Submitting a bug bounty takes time. Also, informing people of security issues can be a virtue which is its own reward.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#48
post #44

Apple has a bug bounty program where they'll legitimately pay you to report bugs directly to them. What's with everyone reporting them to Twitter instead and forgoing the extra cash?

the bounties are low. and registering to those things require some loss of anonymity before you do get paid.

those are users dogfooding a product they paid for. and probably well off already, so the twitter bragging rigths is more valuable than the loss of anonymity + $500.

Re: macOS lock screen: “I just sent my session pass to my whole team”

#50
post #42
post #30

Lock screens are harder than they first appear: www.jwz.org/xscreensaver/toolkits.html (Which, you'll note, mentions this exact failure case in the "Transfer Grabs?" section.) There's some X-specific stuff in there, but there's a lot of general issues in there, and with just a bit of imagination most or all of the X-specific issues can be seen as general issues as well.

Fair warning: Jamie doesn't appreciate the discourse this crowd brings to his site. Visit this URL without a referrer for the best results.

No idea why you wouldn't just make it clear the site will open an inappropriate image when linked from HN

DON'T OPEN THAT LINK

Post reply on HN