[X2Go-Dev] Bug#287: Bug#287: x2goserver allows to connect to ALL X server sessions by default

Mike Gabriel mike.gabriel at das-netzwerkteam.de
Sat Aug 17 21:23:43 CEST 2013


Hi Stefan,

On Sa 17 Aug 2013 21:09:02 CEST Stefan Baur wrote:

> Am 17.08.2013 20:42, schrieb Mike Gabriel:
>>
>>> Or maybe a warning should be issued if "xhost" is set to + when a user
>>> connect?
>>
>> Nope! In default setups no other distro evokes xhost + on session
>> startup. This is just insane!!! So we ignore this issue in X2Go upstream
>> completely.
>
> I'd still vote for adding a check + warning to X2Go.
> Even if this brain-dead setup that is rolled out by Linux Mint isn't  
> the default in other distros, someone might set "xhost +" somewhere,  
> sometime, and totally forget about it.
> A reminder/warning "Hey, you're running X2Go on a host that hast  
> 'xhost +' set, this is a really bad idea", followed by a short  
> explanation, would make sense, IMO.

Any patch is welcome (on the other hand). But do not introduce a  
daemon that checks .Xauthority every five seconds ;-)...

Mike


-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel at das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 836 bytes
Desc: Digitale PGP-Unterschrift
URL: <http://lists.x2go.org/pipermail/x2go-dev/attachments/20130817/99aefcae/attachment.pgp>


More information about the x2go-dev mailing list