Live data from Hacker News

Kids find a security flaw in Linux Mint by mashing keys

github.com

261–270 of 340 posts

Re: Kids find a security flaw in Linux Mint by mashing keys

#261
post #112

Earlier quoted context omitted.

What context? Reading that issue, the content seems to be: 1: jwz says if you add accessibility features to a text box, make sure they don't have any bugs that can kill a process, since that will break screen lockers 2: Cinnamon adds a buggy accessibility feature to a text box that lets you crash the screen locker 3: Github user clefebvre says something along the lines of "why is jwz being so negative >:(" Well... yo…

> Why is it his responsibility to fix your code? The distro extended his program, the extension broke. cinnamon-screensaver (the repo this discussion is pertinent to) is written from scratch. The commenter's intent here is to suggest that JWZ has valid criticisms, but he has voiced them before and his latest blog post doesn't add anything to the discussion. This blog post, which links to the issue, creates additional…

"written from scratch", though it does contain xscreensaver code written by jwz ... and with a copyright changed from BSD to GPL - https://github.com/linuxmint/cinnamon-screensaver/blob/maste... .

The commit is at https://github.com/linuxmint/cinnamon-screensaver/commit/38a... where mtwebster writes:

> We'll use the old screensaver auth code instead - this ports gs-auth-pam.c and gs-auth.h from the old screensaver,

Re: Kids find a security flaw in Linux Mint by mashing keys

#262

Earlier quoted context omitted.

Why?

Cause he redirects based on referrer to https://cdn.jwz.org/images/2016/hn.png

I did not get redirected--would that be because I'm using Brave? Or because I'm on mobile?

Re: Kids find a security flaw in Linux Mint by mashing keys

#263

Earlier quoted context omitted.

It's not an X11 design flaw. The very concept of locking the screen is flawed. A flaw that also haunts Wayland, BTW. The concept of screen lockers is having a special layer, that can't be bypassed, which a locker creates. The whole security then hinges on the locker not crashing. X11 does have such a layer. Wayland compositors also implement it through such a layer. And for either the situation is, that if the locker…

I'm curious what other OS which avoid X11/Wayland do, such as Android. Do they implement an architecture like what you mention?

Windows has a secure desktop that host lock screen. Crash that gives you a bsod or at worst a blank screen (your window did not host on it, whta did you expect?)

Re: Kids find a security flaw in Linux Mint by mashing keys

#264

Earlier quoted context omitted.

Can he at least update the text? HN was full of entrepreneurs and wantrepreneurs years ago. It is mostly big- and mid tech employees now, tech bureaucrats if you will.

Not to belabor the meta discussion, but your comment sparked a question. If it is how you say, and using a politico-economic lens, I wonder if there has been any discernible shift in commenter attitudes as the demographics have changed. Specifically, if the shift was from entrepreneurs -> skilled wage workers, as you’ve asserted. The interests of the petit bourgeoisie (entrepreneurs, et al), the professional manageme…

[deleted]

Re: Kids find a security flaw in Linux Mint by mashing keys

#265

Earlier quoted context omitted.

I would recommend not linking to jwz's website. Use web archive or something if you have to. jwz dislikes Hacker News and intentionally shows an NSFW image when Referer header shows Hacker News.

> .. jwz dislikes Hacker News .. Why, what's the back story?

It has something to do with the 1990's dot-com culture, like the original Netscape was somehow more pure than what came after, and this causes him to view modern inheritors like YC with a jaundiced eye.

You can watch this if you have an hour.

https://youtu.be/4Q7FTjhvZ7Y

Re: Kids find a security flaw in Linux Mint by mashing keys

#266

I find interesting that GNOME Screensaver's security depends on it to not crash. Meanwhile, in KDE the lock screen is managed by KDE Session Management Server which ensures that lock screen cannot be bypassed by simply crashing its process. The way it works is follows: ksmserver draws a black rectangle over everything and spawns kscreenlocker. If kscreenlocker crashes, the black rectangle is still here, and ksmserver…

jwz has a lot to say about complex graphical toolkits/desktop environments and their complex locking mechanisms. It's an interesting series of posts. If you are not running xscreensaver on Linux, then it is safe to assume that your screen does not lock. Once is happenstance. Twice is coincidence. Three times is enemy action. Four times is Official GNOME Policy. https://www.jwz.org/xscreensaver/toolkits.html

I don't think that's the right link mate. I got redirected.

Re: Kids find a security flaw in Linux Mint by mashing keys

#267

Earlier quoted context omitted.

> Our internal research found that clear error messages confused our users and removed it. I can't tell if this is sarcasm or if you're serious. If you're serious, please tell me what product you've butchered so I can avoid it like the plague. Clear error messages only confuse people who shouldn't be using the product in the first place. More importantly: a clear error message at the cost of a few confused users is f…

> I can't tell if this is sarcasm or if you're serious. It is entirely sarcastic, mocking some of GNOME 's more infamous design proclivities.

I'm asking nicely, can we please not do this? Let's not exacerbate the problems of bad communication by using more sarcasm and hyperbole. If there is some particular thing that can be done to improve areas where there are perceived design proclivities, can we focus on that instead?

Re: Kids find a security flaw in Linux Mint by mashing keys

#268

Earlier quoted context omitted.

Cause he redirects based on referrer to https://cdn.jwz.org/images/2016/hn.png

I did not get redirected--would that be because I'm using Brave? Or because I'm on mobile?

The former. Brave has explained their referer policy here: https://brave.com/privacy-updates-5/

> When navigating to a new site, never send a referer header.

JWZ wouldn't know you are visiting from HN if you use Brave.

Re: Kids find a security flaw in Linux Mint by mashing keys

#269

Earlier quoted context omitted.

> I can't tell if this is sarcasm or if you're serious. It is entirely sarcastic, mocking some of GNOME 's more infamous design proclivities.

I'm asking nicely, can we please not do this? Let's not exacerbate the problems of bad communication by using more sarcasm and hyperbole. If there is some particular thing that can be done to improve areas where there are perceived design proclivities, can we focus on that instead?

But it's not constructive criticism, but humor.

I agree that sarcasm provides for poor constructive criticism to get a point across, but the intent was mockery, not being helpful.

I certainly do not believe that GNOME would take the advice of an H.N. post, and they are well aware of these criticisms to begin with, as they are commonly levied against them.

Re: Kids find a security flaw in Linux Mint by mashing keys

#270
post #216

Earlier quoted context omitted.

I would recommend not linking to jwz's website. Use web archive or something if you have to. jwz dislikes Hacker News and intentionally shows an NSFW image when Referer header shows Hacker News.

It's quite nice of Apple to strip this by default in Safari—didn't even realize it was a thing until I switched over to Chrome to see what you were talking about.

I tested Safari on iOS, iPadOS and macOS and it didn’t strip the “referer” header for any of them. WatchOS did strip it though I’m not sure that counts as Safari.
Post reply on HN