-
-
Notifications
You must be signed in to change notification settings - Fork 59
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Howdy's pam module causes unlocks when using reload commands (security risk! DONT use Howdy for Lockscreen unlocks!) #535
Comments
That seems hard to reproduce so I am not going to try for now. |
Hi :) I just build from #536 and tested it - sadly this does not fix the problem. |
@londeril can you maybe also test the new pr #539? Thanks in advance! A bit of context to understand how a problem like this can happen: Hyprlock depends on Based on my current best guess. |
Thanks for the explanation and the change! I just build from pr-539 and tested it - but the bug is still there... if I set the refresh to 1sec., lock my session, cover up my camera and trigger Howdy the system unlocks almost instantly... if I set the refresh to10 seconds, lock the session, cover the camera and count to 10 and trigger howdy just before the image changes the session unlocks... |
That is crazy. I will install howdy and try to reproduce it. I am out of ideas. |
Thanks! let me know if and how I can help! |
It's a pretty bad flaw in howdy's pam module. They use I will open an issue or pr in the howdy repo. But it does not seem like there is a lot of development there. So for now I would advocate for not using howdy. This can be closed on our side. |
For reference: |
@londeril can you change the title to something like "Howdy's pam module causes unlocks when using reload commands". This is also reproducible with label updates. |
WOW! Thanks for all you did! I hope the Howdy team will address this! I'll stop using Howdy to unlock my sessions for the time being and only use it for sudo auth... |
closing |
Regression?
No
Hyprlock Info and Version
Hyprlock version 0.5.0
Hyprlock config
Compositor Info and Version
System/Version info
Description
If Howdy is used to do face-unlock and an image{} widget with an update_cmd is used it can happen that Howdy/Hyprlock auto-unlocks the session without detecting a face.
Since I like a picture slideshow with a 10-ish second refresh on my lockscreen I've stumbled over this issue
How to reproduce
Steps to reproduce
Observations
Crash reports, logs, images, videos
No response
The text was updated successfully, but these errors were encountered: