** Description changed:

  This was reported and supposedly fixed in
  https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1370017, but the
  bug is still present in the current Unity version in Trusty.  I've
  reported it in that bug already, but got ignored, so I'm opening a new
  bug about it.
  
  [Impact and Test Case]
  
  Steps to reproduce:
  1 - Log into Unity
  2 - Open a terminal.
  3 - Lock the screen
  4 - From the lockscreen, tell the computer to shut down / restart
  
  Expected behavior:
  * Session programs are closed while the screen is still locked
  * During shutdown, no user interaction is possible
  
  Observed behavior:
  * The lockscreen is gone immediately, with the rest of compiz (e.g. window 
decorations are not present)
  * But it's possible to interact with programs that are still running in the 
session for about 3 seconds
  
  Observed on an updated Trusty machine, running unity version
  7.2.5+14.04.20150521.1-0ubuntu1
  
  This bug is a security vulnerability because during those 3 seconds it
  could be possible to access and interact with sensitive information.
  Yes, it's short, but you could take a picture or even rm -rf / if there
  happened to be a root console available.
+ 
+ =====
+ 
+ [Impact]
+ A lockscreen should hide the screen content no matter what. A the moment 
there is no easy way to provide a good shutdown experience if the screen is 
locked so it's better to disable it. Please note that shutting down is still 
possible if the screen is locked just switching to unity-greeter using "Swtich 
Account..." but it's safe in this case.
+ 
+ Needs to be backported to 14.04 LTS because can affect security.
+ 
+ 
+ [Test Case]
+ 1 - Lock the screen
+ 2 - Push the hw shutdown button.
+ 3 - Make sure that there is no shutdown option in the end of session dialog.
+ 
+ 1 - Lock the screen
+ 2 - Open the session indicator
+ 3 - Make sure there is no shutdown option in the drop down menu
+ 
+ [Regression Potential]
+ None.

** Description changed:

  This was reported and supposedly fixed in
  https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1370017, but the
  bug is still present in the current Unity version in Trusty.  I've
  reported it in that bug already, but got ignored, so I'm opening a new
  bug about it.
  
  [Impact and Test Case]
  
  Steps to reproduce:
  1 - Log into Unity
  2 - Open a terminal.
  3 - Lock the screen
  4 - From the lockscreen, tell the computer to shut down / restart
  
  Expected behavior:
  * Session programs are closed while the screen is still locked
  * During shutdown, no user interaction is possible
  
  Observed behavior:
  * The lockscreen is gone immediately, with the rest of compiz (e.g. window 
decorations are not present)
  * But it's possible to interact with programs that are still running in the 
session for about 3 seconds
  
  Observed on an updated Trusty machine, running unity version
  7.2.5+14.04.20150521.1-0ubuntu1
  
  This bug is a security vulnerability because during those 3 seconds it
  could be possible to access and interact with sensitive information.
  Yes, it's short, but you could take a picture or even rm -rf / if there
  happened to be a root console available.
  
  =====
  
  [Impact]
- A lockscreen should hide the screen content no matter what. A the moment 
there is no easy way to provide a good shutdown experience if the screen is 
locked so it's better to disable it. Please note that shutting down is still 
possible if the screen is locked just switching to unity-greeter using "Swtich 
Account..." but it's safe in this case.
+ A lockscreen should hide the screen content no matter what. A the moment 
there is no easy way to provide a good shutdown experience if the screen is 
locked so it's better to disable it. Please note that you can still shut down 
the system if the screen is locked just switching to unity-greeter using 
"Swtich Account..." (it's safe in this case)
  
  Needs to be backported to 14.04 LTS because can affect security.
- 
  
  [Test Case]
  1 - Lock the screen
  2 - Push the hw shutdown button.
  3 - Make sure that there is no shutdown option in the end of session dialog.
  
  1 - Lock the screen
  2 - Open the session indicator
  3 - Make sure there is no shutdown option in the drop down menu
  
  [Regression Potential]
  None.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1460626

Title:
  Unity Lockscreen still shows unlocked desktop while shutting down

To manage notifications about this bug go to:
https://bugs.launchpad.net/unity/+bug/1460626/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to