Comment 2 for bug 276530

Revision history for this message
dkg (dkg0) wrote :

I think this *is* a security risk. The danger is not only limited to accidental absent-minded twittering: when the keyboard input is not "grabbed", any application (malicious or not) can eavesdrop on the keyboard input stream. This allows a trivial non-privileged userspace keylogger running in the same Xsession to capture passwords gathered by gaskpass.

It's not clear to me how your window manager affects the keyboard input focus lock. Are you running a window manager that interferes with keyboard grabbing? Can you explain more?

  http://www.pint-stowp.net/software/x11-ssh-askpass/keyboard-grabbing.html

See also XGrabKeyboard(3)