[Bug 807797] New: KDE screensaver vanish without password
https://bugzilla.novell.com/show_bug.cgi?id=807797 https://bugzilla.novell.com/show_bug.cgi?id=807797#c0 Summary: KDE screensaver vanish without password Classification: openSUSE Product: openSUSE 12.3 Version: RC 2 Platform: Other OS/Version: Other Status: NEW Severity: Major Priority: P5 - None Component: KDE4 Workspace AssignedTo: kde-maintainers@suse.de ReportedBy: kukuk@suse.com QAContact: qa-bugs@suse.de Found By: --- Blocker: Yes Installed openSUSE 11.3 RC2 from DVD, created user during installation. After installation, logged in as user, wait some time until KDE locks automatically the screen. If you move the mouse, screen is unlocked without entering the password. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=807797 https://bugzilla.novell.com/show_bug.cgi?id=807797#c1 --- Comment #1 from Stephan Kulow <coolo@suse.com> 2013-03-06 16:57:18 CET --- kcmshell4 screensaver -> you can configure how long the grace period is, the default seems to 60 seconds. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=807797 https://bugzilla.novell.com/show_bug.cgi?id=807797#c2 --- Comment #2 from Thorsten Kukuk <kukuk@suse.com> 2013-03-06 16:10:06 UTC --- I think you misunderstood: the question is not how long the grace period is, the problem is, the screensaver is active and asks you for a password, but if you move the mouse, the screensaver deactivates itself. This is dangerous, because if you look at the screen, you think your desktop is save, but everybody can misuse your account ... If the screensaver does not wait for a password, it should not show a password dialog. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=807797 https://bugzilla.novell.com/show_bug.cgi?id=807797#c3 Raymond Wooninck <tittiatcoke@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED CC| |tittiatcoke@gmail.com Resolution| |WONTFIX --- Comment #3 from Raymond Wooninck <tittiatcoke@gmail.com> 2013-03-06 17:22:13 UTC --- Thorsten, This is the new screen locker functionality that was introduced with KDE 4.10. It is no longer a screensaver, but actually part of the plasma desktop and is called Screen Locker. The initial way was to lock the screen even if the user wanted just a screensaver (without locking the desktop). With the RC's the screen locker functionality was changed so that default the screen is no longer locked if a certain time has passed. Just moving the mouse is enough to get the screen saver out of the way. This particular behaviour can be changed as Stephan indicated by indicating that the Screen should be locked and what time has to pass before the locking actually happens. If the user however chooses from the Desktop that the screen should be locked, then the screen is really locked and a password is required to unlock it. This is the new functionality and is unlikely to change. Feel free to report this upstream, but the picture shown is hard-coded into the locker. Raymond -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=807797 https://bugzilla.novell.com/show_bug.cgi?id=807797#c4 Thorsten Kukuk <kukuk@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |REOPENED CC| |security-team@suse.de Resolution|WONTFIX | --- Comment #4 from Thorsten Kukuk <kukuk@suse.com> 2013-03-06 18:18:07 UTC --- Sorry, but the new behavior is completly inacceptable and a big security problem. If the screen shows "This screen is locked by <user>, please enter the password", I expect that you need the password to be able to access the desktop, and not that moving the mouse is enough. So either make this again a real locking screensaver, or remove the ask for the password box, so that it is clear it's only a screensaver without locking functionality. But letting the user think that the Desktop is secure by not doing so is a no-go. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=807797 https://bugzilla.novell.com/show_bug.cgi?id=807797#c5 Hrvoje Senjan <hrvoje.senjan@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |hrvoje.senjan@gmail.com --- Comment #5 from Hrvoje Senjan <hrvoje.senjan@gmail.com> 2013-03-06 19:59:36 UTC --- Thorsten, we may or may not agree on the severity, but this is certainly a bug that should be both reported, and fixed upstream as Raymond already mentioned. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=807797 https://bugzilla.novell.com/show_bug.cgi?id=807797#c6 Kalenz . <me@kalenz.eu> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|REOPENED |RESOLVED CC| |me@kalenz.eu Resolution| |DUPLICATE Severity|Major |Critical --- Comment #6 from Kalenz . <me@kalenz.eu> 2013-03-07 15:16:14 UTC --- Duplicate of Bug 802959. *** This bug has been marked as a duplicate of bug 802959 *** http://bugzilla.novell.com/show_bug.cgi?id=802959 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com