[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information



Paulo J. S. Silva wrote:
> mac_v,
> 
> You raised very interesting point that the possibility of applications
> asking the user for root access without proving themselves as real
> system applications is a security risk. However I do not think the orage
> icon can solve this problem. It is true that a malicious application can
> fake the update-manager window. But a malicious application can also
> fake the orange icon or whatever notification approach we choose, as you
> are assuming that the "virus" is already running application under user
> privileges.
> 

I did not suggest bringing back the icon , you are probably have me
confused with some other member.

 but i'm for a *better interactive notification system* , in addition to
notify-osd , *which is accessed ONLY by limited system process* . This
way fake notifications dont arise either.

cheers,
mac_v