Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Man, that is pretty crazy. Ctrl+Alt+* and the whole screensaver goes away just like that and everything on the workstation is accessible. Glad this vulnerability is getting more attention; I think it's obvious the feature should only be enabled in debug builds.


It's not yet obvious it was intentional, to my knowledge.


It's pretty obvious that it wasn't intentional. Or rather, that there was some miscommunication. Someone added a debugging feature that gets rid of programs that have grabbed the screen, and which is enabled by mapping some key combination to a function. They probably realized this was dangerous to enable generally. Someone else saw the recommended key combination and packaged it for general distribution, not realizing that it was a dangerous function that shouldn't be mapped ordinarily.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: