Pressing power button unlocks locked screensaver

Bug #37350 reported by Joshua Lock
24
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-screensaver (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Running latest Dapper on iBook G4 (PPC).

I have my screensaver require a password to log back in but it appears the password can be subverted by pressing the power button. This brings up the log out/shutdown/etc screen and pressing cancel returns you to the desktop! Eeek, potential security blunder?

I think either the power-button shortcut should be disabled in locked screen (my preference) or pressing cancel should return you to a locked screensaver.

Tags: apple g4 ppc
Revision history for this message
Dennis Kaarsemaker (dennis) wrote : Re: [Bug 37350] Pressing power button unlocks locked screensaver

Can't confirm on i386 - however, if I press the power button, the logout
dialog will come up after the screen is unlocked. Having pressed it
several times, the dialog come up over and over again. So I agree that
the power button should be completely disabled when the screen is
locked.

Revision history for this message
Michael Farrell (michael-stormy) wrote :

I can confirm this on amd64. I today independantly also discovered this issue, and it's to say the least - embarrasing.

Revision history for this message
Michael Farrell (michael-stormy) wrote :

This is a major issue, I'm confirming this.

Changed in gnome-screensaver:
status: Unconfirmed → Confirmed
Revision history for this message
Andrew Jorgensen (ajorg) wrote :

Same experience as Dennis here. Might make sense to trap all such things when the screen is locked.

Revision history for this message
Ts0 (xxts0xx) wrote : Not necessary press any button :-(

I have a similar experience:
System -> Lock Screen
Then I close the portatil computer and open it: no password is needed!!

(i have dapper drake amd64 on a acer aspire)

Sorry for my english.

Revision history for this message
Lukas Sabota (punkrockguy318) wrote :

Can't confirm on 386

Revision history for this message
Mikko Saarinen (mikk0) wrote :

This doesn't happen to me (using Flight 6 on MSI S250 laptop).

I tested this by locking the screen and suspending the machine with sleep button. Also hibernated it via lid close. Both times when I resumed the session the lock screen came right back.
Power button did not have any action here.

I have a related problem though:

It is set in the /etc/default/acpi-support that the machine should automatically lock the screen on resume:

# Comment this out to disable screen locking on resume
LOCK_SCREEN=true

However this does not happen. Why?

Revision history for this message
Mikko Saarinen (mikk0) wrote :

I found out how to enable the screen locking on resume. It is done by setting the locking on when screensaver is active.

However there are other problems with this setting. After resume, when I have entered my password and the screen unlocks the next thing that happens is that the same screen pops up which comes when pressing the power button. From there I have to push the Cancel to get my desktop back.

So it seems there are still unsettled issues with this gnome-screensaver.

Revision history for this message
Matt Zimmerman (mdz) wrote :

Oliver, if true, this is serious. Please look into it.

Changed in gnome-screensaver:
assignee: nobody → ogra
Revision history for this message
Oliver Grawert (ogra) wrote :

it doesnt happen on my ibook here, i can lock the screen with the lock screen menu item, if i press the power button, that brings up the unlock dialog. unlocking doesnt show the logout dialog or anything here. also pressing the powerbutton multiple times doesnt chage that behavior.

Revision history for this message
Mikko Saarinen (mikk0) wrote :

All of the issues mentioned above seem to be fixed at this point.
There is still one thing worth mentioning before setting this bug as fixed:

When the screen is locked and you press the power button, no pop-up screen is displayed, which is good. But when the password has been entered and the screen unlocks, then the pop-up appears. It only appears if you pressed the power key during the screen lock.

Moreover, if you pressed the power key more than once, the pop-up will reappear after you have selected Cancel. So you have to press Cancel again. This happens as many times as you have pressed the power button. I tried it twice and then three times and so on.

So this is not fixed yet, although it should not be Major anymore. I suggest lowering the severity to normal at this point.

Revision history for this message
Oliver Grawert (ogra) wrote :

good suggestion :)

Revision history for this message
Roland Ronquist (roland-ronquist) wrote :

still, if somebody for administrative reasons, needs to shut down a computer,
reasons ranging from planned power interruptions to office relocations,
it still is nice being able to let somebody shut down the computer in
an orderly fashion.

Hence, the problem was not that a shutdown option was presented
when pressing the power button, the problem was that flicking the
power switch could give somebody full access to the locked
desktop.

It may be that I grew up when power buttons actually had
something to do with the power supply of the device at hand,
but Ubuntu is for "ordinary people" and many such people
still think that the reason for the power switch is switching
the power in a similar way as their light switch is working.

To cater for this conservative mindset, a good workaround
would be skipping the questions about if logout etc and instead
present a simple shutdown yes/no question. OK, that adds
complexity compared to silently bring the machine to a halt,
but it may still save some trouble when the button is pressed
by accident.

Revision history for this message
Chris Cowan (macil) wrote :

If I press the power button while the screen is locked, the "Shutdown the computer" menu comes up (but behind the screen lock - I have to unlock the screen to see it). The bad part is that it informs me it will log me off in 60 seconds, so that means that someone could log me off right from the lock screen.

Oliver Grawert (ogra)
Changed in gnome-screensaver (Ubuntu):
assignee: Oliver Grawert (ogra) → nobody
Revision history for this message
olive (olivier.fraysse) wrote :

I can confirm what Chris wrote on 9.04, without compiz

Revision history for this message
Marius B. Kotsbak (mariusko) wrote :

I can not reproduce this in 11.04 with Unity and 9.04 is no longer supported. Can anybody reproduce this in any current versions (like the LTS)?

Changed in gnome-screensaver (Ubuntu):
status: Confirmed → Incomplete
Revision history for this message
olive (olivier.fraysse) wrote :

can't reproduce in 10.04 and 11.04, amd64.

Changed in gnome-screensaver (Ubuntu):
status: Incomplete → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.