Re: SOLVED: security hole in X????


> As some people suggested, the problem is that the home dir in all
> machines is the same (mounted via NFS from the server), so the
> .Xauthority file is the same. That's why no xhost is necessary.

which of course means that the content of the Authority File is transfered
unencrypted over your net.

