[Pkg-shadow-devel] Bug#305600: Wait a second. This bug is not fixed

Florian Weimer Florian Weimer <fw@deneb.enyo.de>, 305600@bugs.debian.org
Sun, 08 May 2005 20:18:48 +0200


* Martin Quinson:

> So, I reopen this bug just to leave the discussion open and see what
> happens. In my opinion, this is a unfixable bug. Whatever we do in login to
> prevent it could be done by an attacker, too. But I may well be wrong.

One approach is a "secure attention key":

  <http://lwn.net/2001/0322/a/SAK.php3>