Bug 517772

Summary: Fast-user-switching leaves virtual terminals insecure.
Product: [Fedora] Fedora Reporter: Jud Craft <craftjml>
Component: gdmAssignee: Ray Strode [halfline] <rstrode>
Status: CLOSED WONTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: high    
Version: 13CC: bressers, jmccann, rstrode, sergey.rudchenko, theo148, tmraz
Target Milestone: ---Keywords: Security, Triaged
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-06-27 14:20:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 513462    

Description Jud Craft 2009-08-17 04:00:44 UTC
Description of problem:
When switching between virtual terminals using F11's Fast-User-Switching, under certain conditions you may freely switch between logins without ever being prompted to unlock the screen or enter a password.


How reproducible:
All the time.


Steps to Reproduce:
1.  Make two user accounts on a Fedora system, A & B.
2.  Login to A.
3.  Fast-user-switch to B.
4.  Virtual-console-switch back to A (using shortcut form of Ctrl+Alt+F7, etc.)
5.  Unlock A.
6.  Virtual-console-switch to B.  Notice that B does not prompt you for a password.
  
Actual results:
You may now freely virtual-console-switch without ever being prompted for a password.


Expected results:
When switching between open users, you should always be prompted for a password.


Additional info:
It appears that the current terminal is locked when "Switch User" from applet or logout menu is used.

The problem is that when virtual-console-switching AWAY from a terminal, that terminal is not locked.  You may then switch back to it without entering a password.

IE, accounts are only safely locked if you switch away using "Switch User."


Suggestions:
1.  Somehow, detect when the virtual-console is switched, and lock the terminal that the user leaves.
2.  Disable graphical virtual-console-switching.  (IE, the -only- way to switch becomes "Switch User" in logout or user-applet, which safely locks the screen).


More notes:
Generally speaking, it's quite common, but the mere idea of virtual-console-switching is insecure, even in text mode.

It is rather outrageous to disable the text-mode virtual consoles, since these have quite a pedigree and are useful, ex, having multiple logins of the same account (not possible under X/GDM).

However, since the graphical user-switching does not have that use-case, and free graphical-terminal-switching is insecure, it would make sense to disable virtual-console-switching for the graphical terminals.

At least for the graphical logins, you should not be able to freely switch between different accounts without being prompted for credentials.  Neither Mac OS X nor Windows allow you to jump directly between different logged in virtual-terminals:  they force you go back to the login screen.

Comment 2 Jud Craft 2009-11-20 02:48:06 UTC
Would anybody like to at least confirm this bug?  It doesn't seem insignificant.

Comment 3 Tomas Mraz 2009-11-20 09:09:10 UTC
Yes, the problem is there (and it was always there even on the text console switches).

Comment 4 Jud Craft 2009-11-20 22:53:18 UTC
I understand it being there on the text console switches.

However, that seems to be a legacy convention with Linux.  I think that's probably going to be a hard thing to change.

At least it's relatively early enough in life for the new graphical login switch to be designed in a secure manner though.

Comment 5 Sergey Rudchenko 2009-12-27 20:47:33 UTC
Thank you for the bug report.

---

Fedora Bugzappers volunteer triage team
https://fedoraproject.org/wiki/BugZappers




-- 
Fedora Bugzappers volunteer triage team
https://fedoraproject.org/wiki/BugZappers

Comment 6 Bug Zapper 2010-03-15 12:46:16 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 13 development cycle.
Changing version to '13'.

More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 7 Bug Zapper 2011-06-02 17:49:41 UTC
This message is a reminder that Fedora 13 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 13.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '13'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 13's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 13 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 8 Fedora Admin XMLRPC Client 2011-06-21 15:36:05 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 9 Fedora Admin XMLRPC Client 2011-06-21 15:37:24 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 10 Fedora Admin XMLRPC Client 2011-06-21 15:40:19 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 11 Fedora Admin XMLRPC Client 2011-06-21 15:43:02 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 12 Fedora Admin XMLRPC Client 2011-06-21 15:52:40 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 13 Fedora Admin XMLRPC Client 2011-06-21 15:55:28 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 14 Fedora Admin XMLRPC Client 2011-06-21 15:58:01 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 15 Fedora Admin XMLRPC Client 2011-06-21 15:59:09 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 16 Bug Zapper 2011-06-27 14:20:45 UTC
Fedora 13 changed to end-of-life (EOL) status on 2011-06-25. Fedora 13 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.