Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread Vincenzo Ciancia
Il giorno mar, 16/06/2009 alle 19.52 +0530, mac_v ha scritto: > Vincenzo Ciancia wrote: > It would be logical to use this in the modal window that asks for the > password... > When it is in the modal window ,the user will recognize the difference > while entering the password. That'd be much easi

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread mac_v
Vincenzo Ciancia wrote: > It's not offtopic in my opinion as exactly this machinery could be used > in the infamous popup to address the concern of many, but can be moved > elsewhere or dropped if it has obvious flaws that I don't see. > Oh ! no! Pls not in the pop-up... pop-up idea should be re-

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread Vincenzo Ciancia
On 16/06/2009 Paulo J. S. Silva wrote: Thinking a little bit more about Vincenzo suggestion. It is not clear to me how the application that is asking for root access can present some information that is only readable by root. Anyhow, this is a security problem and maybe we are getting off topic

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread Paulo J. S. Silva
Thinking a little bit more about Vincenzo suggestion. It is not clear to me how the application that is asking for root access can present some information that is only readable by root. Anyhow, this is a security problem and maybe we are getting off topic here. best, Paulo ___

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread Vincenzo Ciancia
On 16/06/2009 Natan Yellin wrote: A few websites use a similar trick and display a custom image which the user chooses. I think it's a bit of a better solution than using a phrase, because people are more likely to notice if it changes. Hmm, if I enter "fatti non fummo a viver come bruti" and

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread mac_v
Paulo J. S. Silva wrote: > mac_v, > > You raised very interesting point that the possibility of applications > asking the user for root access without proving themselves as real > system applications is a security risk. However I do not think the orage > icon can solve this problem. It is true tha

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread Natan Yellin
On Tue, Jun 16, 2009 at 1:00 PM, Vincenzo Ciancia wrote: > On 16/06/2009 mac_v wrote: > >> In no way the system should decide what windows it can open... >> If this is allowed it is only a matter of time before someone develops a >> worm which uses this behavior and pops-up a window similar to the

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread Paulo J. S. Silva
mac_v, You raised very interesting point that the possibility of applications asking the user for root access without proving themselves as real system applications is a security risk. However I do not think the orage icon can solve this problem. It is true that a malicious application can fake th

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread mac_v
Vincenzo Ciancia wrote: > > Do you think it is easy to design a webpage that simulates such a > "password fraud"? I see a difficulty here due to having to dim the whole > screen to look like the standard password request, not that an user > would not enter it in any kind of pop-up. > Actually th

Re: [Ayatana] [Fwd: Re: Update manager] - a secure way to ask for information

2009-06-16 Thread Vincenzo Ciancia
On 16/06/2009 mac_v wrote: In no way the system should decide what windows it can open... If this is allowed it is only a matter of time before someone develops a worm which uses this behavior and pops-up a window similar to the update manager which also asks for the user password allowing the