Live data from Hacker News

Kids find a security flaw in Linux Mint by mashing keys

github.com

191–200 of 340 posts

Re: Kids find a security flaw in Linux Mint by mashing keys

#194

I find interesting that GNOME Screensaver's security depends on it to not crash. Meanwhile, in KDE the lock screen is managed by KDE Session Management Server which ensures that lock screen cannot be bypassed by simply crashing its process. The way it works is follows: ksmserver draws a black rectangle over everything and spawns kscreenlocker. If kscreenlocker crashes, the black rectangle is still here, and ksmserver…

I actually had this happen around Christmas (using Manjaro). I had no idea what the message really meant or what caused it. The instructions were at least clear enough to get back into the running session, which is far better than, say, most of GNOME's crap.

Re: Kids find a security flaw in Linux Mint by mashing keys

#195
post #64

Mi kid got around the lock screen of my mac. Twice. It was 4-5 years ago when he was about 2. I had a 15+ character random password (a generated one including symbols etc) so the chances of him being lucky were rather slim. He was just mashing button on the lock screen for less than a minute when boom, I was suddenly signed in. The first time I thought it was a fluke. Then it happened again after a couple of months.…

My 4 year old son manages to beach-ball the big sur lock screen about twice a week. It has resulted in lost work more than once.

On the previous version I believe he managed to unlock the computer as well, just by hammering the keyboard.

Re: Kids find a security flaw in Linux Mint by mashing keys

#196

I find interesting that GNOME Screensaver's security depends on it to not crash. Meanwhile, in KDE the lock screen is managed by KDE Session Management Server which ensures that lock screen cannot be bypassed by simply crashing its process. The way it works is follows: ksmserver draws a black rectangle over everything and spawns kscreenlocker. If kscreenlocker crashes, the black rectangle is still here, and ksmserver…

jwz has a lot to say about complex graphical toolkits/desktop environments and their complex locking mechanisms. It's an interesting series of posts.

  If you are not running xscreensaver on Linux, then it is safe to assume that your screen does not lock. Once is happenstance. Twice is coincidence. Three times is enemy action. Four times is Official GNOME Policy.
https://www.jwz.org/xscreensaver/toolkits.html

Re: Kids find a security flaw in Linux Mint by mashing keys

#197

Step 1: Gather timings of key presses from a lot of kids. 2: Use ML to learn how to simulate it. 3: Sell it as a service, labeling it KaaS. 4: Profit, then go to jail because of a misunderstanding. But seriously, is there such a tool to automate this?

I have been using the name monkey-testing for this kind of testing for as long as I can remember. There are tools to automate it.

Re: Kids find a security flaw in Linux Mint by mashing keys

#198

In middle school long ago, I was using one of the library search computers. They ran Windows XP and were locked down to the point where you couldn't open anything except the software that was running and you had no access to the desktop. One day I was rapidly mashing the "Search" button in the native book-searching software they were using - for no reason at all - and it suddenly opened an Explorer window out of nowh…

Oh man this brings back so much nostalgia for the old school computer exploits we used to find.

Only approved programs software was supposed to run but you could actually run anything as long as the .exe was on the desktop.

7-zip would let you explore the entire network drive, including teachers folders that we didn't have access to.

Unplugging the reconnecting the Ethernet cable wouldn't reconnect you to the teachers monitoring software.

We had a zip filled with games like Starcraft 2, Quake 3, Halo CE that was hidden on the shared network drive that kids around the school would use to play and LAN with each other.

Re: Kids find a security flaw in Linux Mint by mashing keys

#200

Earlier quoted context omitted.

I don't understand the part about JWZ's testicles, so here are the links without bit.ly tracking for those whose ad blockers don't allow them: - https://www.jwz.org/blog/2021/01/i-told-you-so-2021-edition/ - https://www.jwz.org/xscreensaver/toolkits.html [Edit]: I understand now. My browser doesn't send referrer URLs, and I think that's the real fix instead of using something like bit.ly!

You still get the testicles if you click this link, at least using Chrome you do. It's because the referrer field is set to HN so they know where the traffic is coming from.

All good with Brave as far as I can tell. I don't know what everyone is talking about with testicles, but I don't see any with Brave.
Post reply on HN