[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-08-08 Thread Peter Funk
Just another sidenote: I'm unaffected by this bug, because I always use xscreensaver instead of those newer unsecure rewrites. People concerned about security might want to read the http://www.jwz.org/blog/2014/04/the-awful-thing-about-getting-it-right-the-first-time-is-that-nobody-realizes-how-ha

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-28 Thread Oliver Grawert
Just a sidenote: Unlike what the sensationalist article at heise.de from today suggests (which links here), this bug was fixed in a heroc effort over night *before* final release, the fix is on the 14.04 image that was released to end users. -- You received this bug notification because you are a

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-27 Thread Marc Deslauriers
Yes, bug 49579 won't get fixed until we move away from xorg into Mir... -- You received this bug notification because you are a member of DX Packages, which is subscribed to unity in Ubuntu. Matching subscriptions: dx-packages https://bugs.launchpad.net/bugs/1308572 Title: Ubuntu 14.04: securi

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-27 Thread Seth
@kristian-erik-hermansen Cool find, but utterly irrelevant here. That bug is about users blindly trusting the screen to auto-lock (which they _should be able to_). This bug is about the trust being broken even after they _verified_ that they had _explicitly_ locked their screens. That's (a) a very

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-27 Thread Kristian Erik Hermansen
This Lock Screen bug is just one of many unfixed security issues. Below is another long-standing issue that also allows one to bypass the lock screen... https://bugs.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/49579 -- You received this bug notification because you are a member of DX Pac

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-17 Thread Brandon Schaefer
** Changed in: unity Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of DX Packages, which is subscribed to unity in Ubuntu. Matching subscriptions: dx-packages https://bugs.launchpad.net/bugs/1308572 Title: Ubuntu 14.04: security pro

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-17 Thread Andrea Azzarone
** Changed in: unity Status: In Progress => Fix Committed ** Tags added: lockscreen -- You received this bug notification because you are a member of DX Packages, which is subscribed to unity in Ubuntu. Matching subscriptions: dx-packages https://bugs.launchpad.net/bugs/1308572 Title:

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Treviño
robru: the fact that unity doesn't reload properly after some crashes it's related to to bug #1308800 (it seems upstart is not loading unity, so gnome-session is not reliable at all for this). -- You received this bug notification because you are a member of DX Packages, which is subscribed to un

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Launchpad Bug Tracker
This bug was fixed in the package unity - 7.2.0+14.04.20140416-0ubuntu1 --- unity (7.2.0+14.04.20140416-0ubuntu1) trusty; urgency=low [ Andrea Azzarone ] * Do not allow to activate twice the same entry! (LP: #1308572) [ Marco Trevisan (Treviño) ] * UnityScreen: save a locked.

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Treviño
** Branch unlinked: lp:~3v1n0/unity/relocks-on-crashes -- You received this bug notification because you are a member of DX Packages, which is subscribed to unity in Ubuntu. Matching subscriptions: dx-packages https://bugs.launchpad.net/bugs/1308572 Title: Ubuntu 14.04: security problem in the

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Robert Bruce Park
So both the linked branches built in silo 8, and when I tested it, this is what I found: 1. start unity 2. open terminal (Ctrl+alt+T) 3. type 'sleep 15 && killall -9 compiz' 4. lock screen observe: screen locks, then unity crashes, then unity restarts locked. so far so good. 5. issue the same

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Launchpad Bug Tracker
** Branch linked: lp:~3v1n0/unity/relocks-on-crashes -- You received this bug notification because you are a member of DX Packages, which is subscribed to unity in Ubuntu. Matching subscriptions: dx-packages https://bugs.launchpad.net/bugs/1308572 Title: Ubuntu 14.04: security problem in the l

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Launchpad Bug Tracker
** Branch linked: lp:~andyrock/unity/fix-1308572 -- You received this bug notification because you are a member of DX Packages, which is subscribed to unity in Ubuntu. Matching subscriptions: dx-packages https://bugs.launchpad.net/bugs/1308572 Title: Ubuntu 14.04: security problem in the lock

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Andrea Azzarone
** Changed in: unity Assignee: Marco Trevisan (Treviño) (3v1n0) => Andrea Azzarone (andyrock) ** Changed in: unity (Ubuntu) Assignee: Marco Trevisan (Treviño) (3v1n0) => Andrea Azzarone (andyrock) ** Changed in: unity Milestone: None => 7.2.1 -- You received this bug notification

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Brandon Schaefer
** Description changed: affects ubuntu Hello, I am running Ubuntu 14.04 with all the packages updated. When the screen is locked with password, if I hold ENTER after some seconds the screen freezes and the lock screen crashes. After that I have the computer fully unlocked. --

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Brandon Schaefer
** Changed in: unity Assignee: (unassigned) => Brandon Schaefer (brandontschaefer) ** Changed in: unity (Ubuntu) Status: Triaged => In Progress ** Changed in: unity Status: Triaged => In Progress ** Changed in: unity (Ubuntu) Assignee: (unassigned) => Brandon Schaefer (br

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Adam Conrad
To be clear, the "always restart locked" half of the fix is the more important bit. The crash is embarrassing, but crashes will happen, and we'll find others. Having it restart unlocked is bordering on unforgivable, and we should focus on fixing that first. -- You received this bug notification

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Brandon Schaefer
** Also affects: unity Importance: Undecided Status: New ** Changed in: unity Status: New => Triaged ** Changed in: unity (Ubuntu) Status: New => Triaged ** Changed in: unity Importance: Undecided => Critical ** Changed in: unity (Ubuntu) Importance: Undecided => C

[Dx-packages] [Bug 1308572] Re: Ubuntu 14.04: security problem in the lock screen

2014-04-16 Thread Iain Lane
** Package changed: gnome-screensaver (Ubuntu) => unity (Ubuntu) -- You received this bug notification because you are a member of DX Packages, which is subscribed to unity in Ubuntu. Matching subscriptions: dx-packages https://bugs.launchpad.net/bugs/1308572 Title: Ubuntu 14.04: security prob