sysinstall and xscreensaver

Jamie Zawinski jwz at jwz.org
Tue Apr 8 19:32:05 PDT 2003


Shane Helms wrote:
> 
> Against a determined adversary, xlockmore is probably (?) a bit more
> secure than xscreensaver

Excuse me?  In what bizarro-universe can you possibly imagine xlockmore
to be more secure than xscreensaver?

The xlock/xlockmore model (of running the graphics demos and security
code in the same address space) is *fundamentally* broken from a
security standpoint.  With xscreensaver's design, a fault in the
eye-candy code will not cause the screen to unlock, as happens with
xlock/xlockmore.

In detail: http://www.jwz.org/xscreensaver/versus-xlock.html

-- 
Jamie Zawinski
jwz at jwz.org             http://www.jwz.org/
jwz at dnalounge.com       http://www.dnalounge.com/


More information about the freebsd-questions mailing list