[Bug 1948339] Re: Logon screen can be bypassed using various shortcuts

2022-04-25 Thread Bastian Kanbach
Hi all, thanks a lot, I upgraded to MATE 22.04 and could confirm that marco is no longer recognising its keybindings. --- However I discovered a second issue some minutes ago: I installed MATE 22.04 on another system with some special keys on the keyboard and one of the keys (Fn + F9) on the

[Bug 1948339] Re: Logon screen can be bypassed using various shortcuts

2022-04-12 Thread Bastian Kanbach
That sounds great, thank you very much. I guess it's an optimal way to keep the marco look-and-feel and have it invoked securely at the same time. Could there be a scenario where arctica-greeter is upgraded on a system but marco is not? (e.g. arctica-greeter invoking "marco --no- keybindings"

[Bug 1948339] Re: Logon screen can be bypassed using various shortcuts

2022-03-04 Thread Bastian Kanbach
Exactly, so at the moment only the following are affected: - impish - jammy I've added a few comments to the arctica-greeter repo and issued a pull request that basically reverts the commit that introduced the weakness. However this still needs to be reviewed by the maintainers -- You

[Bug 1948339] Re: Logon screen can be bypassed using various shortcuts

2021-12-24 Thread Bastian Kanbach
Hi all, narrowed it down and found out that arctica-greeter is invoking "marco" to make handling of windows opened by some of the indicators easier. However marco listens for any keybindings and that's the reason why keybindings are working on the logon screen. The affected code path was

[Bug 1948339] Re: Logon screen can be bypassed using various shortcuts

2021-10-22 Thread Bastian Kanbach
Thanks :) I haven't registered a CVE yet and I'm waiting for final confirmation which components are causing the described issue. Happy to contribute to the ArcticaProject issue tracker directly. As you also mentioned I can confirm that the affected arctica-greeter version is present in the