Announcement

Collapse
No announcement yet.

Session security problem

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Session security problem

    Hello everyone, I have detected a problem related to the user switching / logout functionality in Kubuntu 17.10. I can not really tell if it's a distro-related issue or KDE.

    The steps are:

    1 - I login with my user
    2 - I switch to another user
    3 - After working, I log out of this user.

    In my understanding, the system should request the login screen again, so that another user could login, but instead goes back to the previous session fully open without asking for any password.

    This behavior was not so in version 17.04 and this creates a major security problem.

    I am available for more details.

    Thank you,

    Pugbrain

    #2
    Check your "Desktop Sessions" settings under "Startup and Shutdown."
    If you think Education is expensive, try ignorance.

    The difference between genius and stupidity is genius has limits.

    Comment


      #3
      Originally posted by pugbrain View Post
      Hello everyone, I have detected a problem related to the user switching / logout functionality in Kubuntu 17.10. I can not really tell if it's a distro-related issue or KDE.

      The steps are:

      1 - I login with my user
      2 - I switch to another user
      3 - After working, I log out of this user.

      In my understanding, the system should request the login screen again, so that another user could login, but instead goes back to the previous session fully open without asking for any password.

      This behavior was not so in version 17.04 and this creates a major security problem.

      I am available for more details.

      Thank you,

      Pugbrain
      If you wan't the password query when returning - use the lock screen:

      1) Lock screen



      2) Start new session or switch session



      .
      .
      .

      N) When returning to the first session it is locked:

      Last edited by Rog131; Nov 03, 2017, 04:17 PM.
      Before you edit, BACKUP !

      Why there are dead links ?
      1. Thread: Please explain how to access old kubuntu forum posts
      2. Thread: Lost Information

      Comment


        #4
        Thanks for replying,. The desktop session settings are these (Brazilian Portuguese):

        Comment


          #5
          Thanks for the feedback Rog131,

          Yes this is an option, but this was not behavior in version 17.04. Which in my point of view was safer.

          Pugbrain

          Comment

          Working...
          X