linuxdeepin / dde-session-ui

dde-session-ui module
GNU General Public License v3.0
33 stars 57 forks source link

dde-lock vulnerability, interaction with the screen-locked system #155

Closed sha0coder closed 3 years ago

sha0coder commented 5 years ago

Hello, it is possible to interact with the screen-locked system under certain situations. The apps can map some keys that can be trigeered even with the screen locked. For example in the case of a VirtualBox, with the screen-locked you can press [Ctrl] key to set the focus on the VM then all the keys are sent to the VM. I managed to open a CMD and a calculator, with the screen locked. But this is not just a problem with VM's, the app-level key binding are still enabled when the screen is locked.

regards.

BLumia commented 5 years ago

cc @hualet

justforlxz commented 3 years ago

Sorry, this issue will be closed soon. If it is necessary to discuss it again, please create a new issue.