dx-packages team mailing list archive
-
dx-packages team
-
Mailing list archive
-
Message #41036
[Bug 830348] Re: desktop contents briefly visible on resume from suspend before lock dialog
*** This bug is a duplicate of bug 1280300 ***
https://bugs.launchpad.net/bugs/1280300
Yep still get it in 17.04, also to be noted is that while using vmware,
the desktop does not lock until I click on something else, causing the
vm to lose input focus. So I can leave my computer for far longer than
the set lock time and it will not lock until somebody clicks somewhere
on the unity launcher or another window. IDK how this has existed since
2011, this is a glaring security bug.
--
You received this bug notification because you are a member of DX
Packages, which is subscribed to unity-2d in Ubuntu.
https://bugs.launchpad.net/bugs/830348
Title:
desktop contents briefly visible on resume from suspend before lock
dialog
Status in Compiz:
New
Status in unity-2d:
Confirmed
Status in gnome-screensaver package in Ubuntu:
Incomplete
Status in unity-2d package in Ubuntu:
Confirmed
Bug description:
This seems like a recent regression on Oneiric (or perhaps I haven't
noticed it before):
On resume from suspend, the contents of the desktop are often briefly
visible before being hidden behind the lock screen. This is a
security problem if there happens to be sensitive information on the
screen.
=====Analysis from mdeslaur=====
This is likely what happens:
1- Something grabs mouse: ie: virtual machine window, or GTK menu in an application or an indicator
2- Screensaver attempts to start, but cannot get exclusive lock on mouse
3- DPMS turns monitor black
4- User moves mouse, which turns the screen back on
5- Mouse movement causes mouse to get ungrabbed by vm window or gtk menu
6- Screensaver can now grab mouse, and starts
This is all related to the fact that X does not have an API that will
let the screensaver tell an application to release mouse and keyboard
grabs.
To manage notifications about this bug go to:
https://bugs.launchpad.net/compiz/+bug/830348/+subscriptions