Bug#474785: [Plash] Re: [cap-talk] Plash: Empowering Security

2008-04-10 Thread Timo Lindfors
Hi, Mark Seaborn <[EMAIL PROTECTED]> writes: > By default "ssh -X" doesn't use the XSecurity extension on Debian or > Ubuntu. See "ForwardX11Trusted" on the ssh_config man page. I think Now, that was an interesting observation! I can see it in the man page now that I specifically look for it bu

Bug#474785: [Plash] Re: [cap-talk] Plash: Empowering Security

2008-04-08 Thread Mark Seaborn
On Tue, 2008-04-08 at 01:08 +0300, Timo Lindfors wrote: > Mark Seaborn <[EMAIL PROTECTED]> writes: > > X11 access is not quite innocuous. :-) X is a big can of worms that > > will require a lot of work to make safe. [2] > > Indeed. I today noticed that even with 'ssh -X' remote host can log > eve