regolith-linux / regolith-desktop

Meta package for the Regolith Desktop Environment
1.48k stars 31 forks source link

X session lock screen bypass #916

Open twvd opened 9 months ago

twvd commented 9 months ago

Describe the bug You can bypass the lock screen with a few keystrokes for the X session.

To Reproduce Steps to reproduce the behavior:

  1. Click the password field
  2. Press the context menu key on the keyboard, context menu appears
  3. Press Super+Shift+R
  4. Wait a few seconds
  5. Repeat step 2 + 3
  6. Screen is unlocked

Expected behavior Screen remains locked.

Configuration file(s) No customizations.

Installation Details

jrn90 commented 9 months ago

I tried this on my machine and can duplicate the same behavior.

kgilmer commented 9 months ago

This bug has been reported in the past. People have found other ways of bypassing the lockscreen as well. You may have better luck by specifying a different lockscreen implementation. I believe the sway-based session also should not suffer from this bug.