Bug 280051 - focus stealing allows keystroke hijacking
Summary: focus stealing allows keystroke hijacking
Status: RESOLVED DUPLICATE of bug 80897
Alias: None
Product: kde
Classification: I don't know
Component: general (show other bugs)
Version: 4.7
Platform: openSUSE Linux
: NOR major
Target Milestone: ---
Assignee: Unassigned bugs mailing-list
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-08-13 22:27 UTC by bkorb
Modified: 2011-08-14 09:50 UTC (History)
1 user (show)

See Also:
Latest Commit:
Version Fixed In:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description bkorb 2011-08-13 22:27:35 UTC
Version:           4.7 (using KDE 4.7.0) 
OS:                Linux

RE: Bug 80897
Since that bug is listed as a "wish list" and since the problem is a security issue, either that bug needs to be re-interpreted as a severe bug or else a severe bug needs to be raised as the severe problem.  Focus stealing is not a wish list item.

Reproducible: Always

Steps to Reproduce:
1. fire up a key logger program under some sort of delay.
2. Log in to your financial institution.  Time it so you
   are typing your password when #1 wakes up and steals focus

Alternatively:

1. spend all day working on some document
2. have a popup steal a few keystrokes
3. let the remaining keystrokes in the buffer mean,
   "quit now and discard everything"

The first has never happened to me, but the latter *almost* has.

Actual Results:  
I swallow my heart back down out of my throat and do the right thing.

Expected Results:  
I expect my keystrokes to arrive at the window that was under focus when I started typing them and not delivered to some popup.  I also do not expect focus stealing to move my current desktop to another one.

It's been 7 years now since the issue was raised.  It is not a trivial issue.  It is important.  Thank you.
Comment 1 Christoph Feck 2011-08-13 23:15:09 UTC
I fail to understand what the difference between this bug and bug 80897 is. We do not need two reports if they are about the same bug. Please clarify.
Comment 2 bkorb 2011-08-14 00:20:19 UTC
The difference between them is seven years.  Someone marked that as a wish list item, and after seven years, it seems equivalent to saying, "we don't think your security issue is important".  So, raise the priority of bug 8097 and close this, or close that one and leave this open on the theory that seven year old bugs don't get the attention they should.  This is fresher.
Comment 3 Christoph Feck 2011-08-14 09:50:24 UTC
Given the fact that bug 80897 (the original report) has more additional comments and more votes, I decided to keep the old report and mark this one as a duplicate.

I will also add a comment (in addition to the duplication notice) about what has been discussed here.

*** This bug has been marked as a duplicate of bug 80897 ***