Security Audit Request for Screenlocker Branch

Thomas Lübking thomas.luebking at gmail.com
Tue Oct 11 16:47:13 BST 2011


Am Tue, 11 Oct 2011 17:00:46 +0200
schrieb Martin Gräßlin <mgraesslin at kde.org>:

> that is a good suggestion. I will think about how I can add that.
> Though if someone breaks by crashing kwin he is also able to remove
> any log. So this could be just snakeoil.
He'll be able to click away the message, yes.

But unless you intend to put a file into the users $HOME ... man:syslog
(crashing the screenlocker does not mean to raise privileges, you're
pretty screwed in that case, but that's not a a kwin issue)

Cheers,
Thomas




More information about the kde-core-devel mailing list