|
|
Log in / Subscribe / Register

Might be a good move

Might be a good move

Posted Jun 24, 2025 21:36 UTC (Tue) by Cyberax (✭ supporter ✭, #52523)
In reply to: Might be a good move by linuxrocks123
Parent article: GNOME deepens systemd dependencies

> Sure, I guess theoretically you could buffer overflow the username or password field

Some password greeters can do remote calls to LDAP, there can be greeters that can do a 3D scan of your face with a call to a remote service to validate it, etc. That's quite a sizeable attack surface.

And I have personally seen a greeter that opens a browser and does an SSO login to retrieve the user's details.


to post comments

Might be a good move

Posted Jun 25, 2025 3:35 UTC (Wed) by linuxrocks123 (guest, #34648) [Link]

> And I have personally seen a greeter that opens a browser and does an SSO login to retrieve the user's details.

I actually wrote a greeter like that for a university! The browser was locked down, of course. It was a very unusual set of requirements.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds