On Sunday 12 February 2006 07:38, Christian Mueller wrote:
> I'm talking about the things my ssh client *doesn't* ever get to see =

> let alone send it to a compromised server counterpart, for example =

> passwords I enter in my locally running browser. This too can =

> be snooped if X11 forwarding is on (because the X11 API allows it =

> and "ssh -X" forwards the X11 requests). =A0

Your passwords can be recovered by exploits running in user mode
independent of ssh and/or x11 forwarding. x11 is beginning to look
to me as about as secure as Microsoft Windows.
