[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#909020: marked as done (ITP: xsecurelock -- XSecureLock is an X11 screen lock utility designed with the primary goal of security.)



Your message dated Thu, 05 Sep 2019 08:11:10 +0000
with message-id <E1i5mrG-000IbU-Vz@fasolo.debian.org>
and subject line Bug#909020: fixed in xsecurelock 1.4.0-1
has caused the Debian Bug report #909020,
regarding ITP: xsecurelock -- XSecureLock is an X11 screen lock utility designed with the primary goal of security.
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
909020: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909020
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: wnpp
Owner: Markus Teich <mteich@google.com>
Severity: wishlist

* Package name    : xsecurelock
  Version         : 1.0
  Upstream Author : Rudolf Polzer <divVerent@gmail.com>
* URL             : https://github.com/google/xsecurelock
* License         : Apache-2.0
  Programming Lang: C, Bash
  Description     : XSecureLock is an X11 screen lock utility designed with the primary goal of security.


XSecureLock allows users to protect their active X11 sessions by covering up the screen until the user enters his password.


Screen lock utilities are widespread. However, in the past they often had
security issues regarding authentication bypass (a crashing screen locker would
unlock the screen), information disclosure (notifications may appear on top of
the screen saver), or sometimes even worse.

In XSecureLock, security is achieved using a modular design to avoid the usual
pitfalls of screen locking utility design on X11.


- XSecureLock is most similar to i3lock, slock or xscreensaver, but focuses more on security (which is hard in X11). For example, xsecurelock "outsources" the rendering and authentication to separate processes which can crash or fail without the screen being unlocked. The main process that holds the lock has a very limited scope to avoid the chance for fatal bugs or vulnerabilities. More details can be found at https://github.com/google/xsecurelock#security-design.

- The upstream code will be maintained by the original author (Rudolf Polzer) and myself.

- I already know two people who offered to sponsor the upload.
--
Google Germany GmbH, Erika-Mann-Str. 33, 80636 München, Geschäftsführer: Paul Manicle, Halimah DeLaine Prado, Registergericht und -nummer: Hamburg, HRB 86891, Sitz der Gesellschaft: Hamburg
This e-mail is confidential. If you received this communication by mistake, please don't forward it to anyone else, please erase all copies and attachments, and please let me know that it has gone to the wrong person.

--- End Message ---
--- Begin Message ---
Source: xsecurelock
Source-Version: 1.4.0-1

We believe that the bug you reported is fixed in the latest version of
xsecurelock, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 909020@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Markus Teich <mteich@google.com> (supplier of updated xsecurelock package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 11 Jun 2019 23:20:34 +0200
Source: xsecurelock
Binary: xsecurelock xsecurelock-dbgsym
Architecture: source amd64
Version: 1.4.0-1
Distribution: unstable
Urgency: medium
Maintainer: Markus Teich <mteich@google.com>
Changed-By: Markus Teich <mteich@google.com>
Description:
 xsecurelock - X11 screen lock utility with the primary goal of security
Closes: 909020
Changes:
 xsecurelock (1.4.0-1) unstable; urgency=medium
 .
   * Initial upload (Closes: #909020)
   * Upstream version 1.4.0
Checksums-Sha1:
 0a8aa8072bf8d449b1d0c999ca747af0d1bf3b14 2062 xsecurelock_1.4.0-1.dsc
 ede2fc68c941d690a8efab7000f8a54c9148a301 213054 xsecurelock_1.4.0.orig.tar.gz
 c43bdc9c27ed54f87142dd6fe4faef8ee09becfd 2540 xsecurelock_1.4.0-1.debian.tar.xz
 71b5b6b7844d2a006ff6cfa7f8c6abf083c0897d 146952 xsecurelock-dbgsym_1.4.0-1_amd64.deb
 1bd9bf7bb04f64af963eaaea8e01a644b3d47c3b 7487 xsecurelock_1.4.0-1_amd64.buildinfo
 bb6209831cce60bd6e79321cf19140446bdf023a 65740 xsecurelock_1.4.0-1_amd64.deb
Checksums-Sha256:
 6b0b2acc152a4f6850149042779d271045b1befb5aa757bce7502f7d6f6a4e60 2062 xsecurelock_1.4.0-1.dsc
 fc16f956b0c131954fe31f8f34766e0f41f2c900d1f4d00a10a382190b5ada9b 213054 xsecurelock_1.4.0.orig.tar.gz
 a6c2b54c2e9026f272fcf070c3d1b32a8d669912034527fa40b7d949e1440028 2540 xsecurelock_1.4.0-1.debian.tar.xz
 3d4b9df46cdf65816203fc8708488398d5b89b2b66fbcd2e18fd1814d1229acc 146952 xsecurelock-dbgsym_1.4.0-1_amd64.deb
 7cc7ecc3710462f1c2663837c51debfec953741b86eb97ec1771f5386045e332 7487 xsecurelock_1.4.0-1_amd64.buildinfo
 9249eaa48847ef6beb0ad830c378c55786271c62f7f52047081ed959ee366298 65740 xsecurelock_1.4.0-1_amd64.deb
Files:
 fc9bddaf5c2d709ddf1cda00ff7b1846 2062 x11 optional xsecurelock_1.4.0-1.dsc
 146ceda7a8ae1798a17ec6e6bae9b083 213054 x11 optional xsecurelock_1.4.0.orig.tar.gz
 d96748bd6d32d2906a6a3dd5fb436a62 2540 x11 optional xsecurelock_1.4.0-1.debian.tar.xz
 489230f2ed730f593b44b8c335689182 146952 debug optional xsecurelock-dbgsym_1.4.0-1_amd64.deb
 ae5c38bf0466d84299bdef7ee4a0bc09 7487 x11 optional xsecurelock_1.4.0-1_amd64.buildinfo
 1479fc7d05d5ca6e97204686e4da6b0b 65740 x11 optional xsecurelock_1.4.0-1_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE+JIdOnQEyG4RNSIVxxl2mbKbIyoFAl0Cg28ACgkQxxl2mbKb
Iypprg//a+lR6TbM8rrf567jpjHo1nblBF/yQ7IXHljoucZmGhmaz22YBJ6PyxhX
fk2Il+CW5T+eJCzvn/IXRNlChvQIlwlFHW1L0y6kvBNlUb+gPeKGQrkyHY30QXVe
PBLlPaZGH2CALckRC5If+HoGjrHoEJHI1seXI9ampXMkOa1x8yO/OZjVJuuH7lxX
615Poau1bJLMr4mMeLqH2sWNBCYRiXf4nupmqQ8anI/y65q8sK2+rYOLUkpHPYE5
TghWUkqrvHfoiW3QPkFjWO5DFwW/ptkWB1bZvAhh39trQbZNIfIecuvrO3dJHnGc
Mqt/n1rxap9k9oeBl1FoZ+/LeVLkN/ueSG6/zAKQUiWLGt5S8GX6D+DQT0Mf/8w0
Ede2Fs72PIxIEbtUaXq1+3c3YTERdLJbMNBiJXUaLg9Z/tS3jcn1vCKBPZhKBghW
qf2nVkYboUWZzTxq/y9UJLCi9wRMYhl32zR7L2KBM11hmbLnZp+GdzsAg1X6jGdj
a7pHRBhnX9N0rvs8Gjenkzp1uyrO+/zjX8CrxTAnbzJMKShR0ciyCqnxRygDfF5w
td/bCrDlr3SVKOPJchTVPjWoXsey2t/PvllV2O5PIXoe7aA5dCeA2WKCPBA5A0Gt
8bB1QLgMqkJIBZgdAhZtbXPpn4oitRtEMUoTQdNoZUAu6VeK3E4=
=FDQC
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: