Hacker News new | past | comments | ask | show | jobs | submit login

In fact jwz himself says in that very post that it is a fundamental problem with X11:

> X11 ... was designed with no security to speak of, and so lockers have to run as normal, unprivileged, user-level applications. ... This mistake of the X11 architecture can never, ever be fixed.

He also claims in the second post that Xscreensaver is actually vulnerable to exactly the same kind of attack:

> The xscreensaver daemon is a critical piece of security software. The reason for this is that, as a screen locker, any bug in the program that causes it to crash will cause the screen to unlock. As soon as xscreensaver is no longer running, the screen is no longer locked. Therefore, great care must be taken to ensure that the daemon never crash.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: