On Sunday 12 February 2006 16:34, Fred Emmott wrote:
> [snip]
> >
Xspy and xkey are key logging programs. I got one of these programs
to log kde konsole keystrokes to a different user login running in
console mode after I ran xhost + in the kde session.
> >

> [snip]
Not looked at the programs, however "xhost +" is a command specifically
designed to disable X11's security, therefore this is not a security hole.

Upon reflection, I understand your point. But astonishment is increasingly my state
as I learn about how x11 security works in practice.

