← Back to context

Comment by pritambaral

10 years ago

Is the "secure desktop with dimming effect" not spoofable?

It probably is, but it would be near-impossible for a respectable company to claim that they weren't specifically trying to spoof it.

With the current OS X password prompt being a benign looking window, Dropbox (or others) can easily say they're just "following standard UI patterns" or something like that.

Trivially, in fact, KeePass does a fairly good job of it, mimicing everything down to the actual creation of a second, "secure" desktop. It's arguably more secure, though it's a little bit of a "false security", as KeePass's "Secure Desktop" is not as "secure" as the UAC and similar one, as the UAC one runs as SYSTEM, where as KeePass's runs as the current user.

Not really. Sure you can make a replica of it but it won't behave the same because you'll be able to minimize or close it but the secure desktop you can't do jack to until you either accept to decline whatever it's asking.

  • Disable the minimize button? Hook into alt tab? There's endless opportunities!

    • I mean sure and that may confuse the normal users. But if I remember correctly you can't override / replicate everything without administrative access. If I remember correctly ctrl + alt + del can't be overridden on the security screen. I thought there were other things as well.

      1 reply →

  • >you can make a replica of it but it won't behave the same because you'll be able to minimize or close it

    but it would still achieve its purpose of phishing a root password