13 ms·
macOS lock screen: “I just sent my session pass to my whole team”
- rst 9y agoEven more fun if the focus happens to be on a terminal window...
- breakingcups 9y agoI knew I shouldn't have picked 'rm -rf /' as a password
- teekert 9y agoHaha, tried that a couple of months back before wanting to do a reinstall. The system stopped me with some warning :) I think it was Arch but could have been Ubuntu or Solus.
- p7IDD243 9y agoYep, nowadays rm has a failsafe and requires you to add --no-preserve-root argument if you want to force remove the root folder recursively.
- Gloire_a_Satan 9y agoThere's a way to still do the rm -rf / bypassing the warning but you shouldn't do that. Ever since systemd was a thing, that command has stopped being 'safe'. It no longers solely affect the filesystem. It can wipe your EFI variables and make your comnputer unable to boot at all, even unable to boot installers to reinstall linux. https://github.com/systemd/systemd/issues/2402 https://github.com/systemd/systemd/issues/2402 Don't think of the file system as just the file system. If you keep thinking of / as only meaning 'whatever's in that hard drive' you will not like what you may encounter.
- __david__ 9y agoOh, you're lucky. Mine is 'rm -rf --no-preserve-root /'.
- tachion 9y agoIf it's not there, you can always make it be, like I did in past with very similar issue (described in another comment). Quite few people disable/change OS wide keyboards shortcuts ;)
- sigzero 9y agoHow about people stop releasing this sh*t on twitter?
- djsumdog 9y agoMost people not in tech or infosec have never heard of and are totally uneducated about the concept of responsible disclosure. Maybe it needs to be added to high school computer class?
- wyuenho 9y agoExcept this dude on Twitter is. I wonder how many people in tech actually know about responsible disclosure.
- jimmies 9y agoPlus, even if you understand that, the thrill of having a shot at gaining thousands of followers instantly (like the root empty password guy) if you get lucky and get covered by news outlets is a great incentive for people to not responsibly disclose the security problem. If you responsibly disclose to Apple, it's their mercy to give you any reporting privileges, pay attention to you, and credit you. That to me is not the right way to think, but in the day and age where number of likes and followers is king, I'd say it's not too irrational.
- theOnliest 9y agoBut this doesn't really need to be responsibly disclosed: it's not something someone can use to get into your machine, but rather a way you could accidentally broadcast your credentials somewhere unexpected. Announcing on Twitter seems more like "hey be careful, make sure your password field is focused."
- TonnyGaric 9y agoYes, you can not get into someone else's Mac. However, what if the last opened application was Terminal? I can think of several scenario where you can do "damage" without logging in—if this bug is real—depending on the last opened application.
- donmb 9y agoCould not reproduce that. For me its impossible to not have the password field focused. Hm?
- ankushnarula 9y agoSame here. Running 10.12.6
- CameronBanga 9y agoI think this is a 10.13-only bug, likely tied with some of the other password entry bugs that have popped up due to a bunch of rework with how user login/authentication work.
- FLUX-YOU 9y ago>For me its impossible to not have the password field focused Maybe Slack or other apps have to call for focus, and MacOS is allowing those calls while it's locked.
- atonse 9y agoChrist are these people just looking for attention or what? Why don't they take a second to follow some kind of responsible disclosure policy? Plus you can get bug bounty money probably if you do this the correct way.
- tachion 9y agoNo you don't, at least not from Apple, as it was the case when I reported a very similar issue few years ago. ;)
- bsaul 9y agoI think in the specific case of apple, this serves a nice purpose. I believe macOS has lost a bit of love from the company, and so it’s a nice way (if not the only way) to make management listen.
- valine 9y agoApple’s bug bounty program is for iOS only. There isn’t a bounty program for macOS.
- ulldma 9y agoAnd their iOS bug bounty program is invitation-only.
- CameronBanga 9y agoYou've obviously never filed a bug with Apple if you think you could get bug bounty money, or really anything other than "FILED AS DUPLICATE OF RDAR://198017630131903".
- pilif 9y agoI did something similar too - I was typing in the password while the Mac was being unlocked by the watch using that unlock-with-the-watch feature. I was used to hammering return a few times to wake the machine up, then typing in the password, then hitting return again. The few times I hammered return woke the machine, the watch unlocked the mac and the password plus the return key went into the app that had focus which for me also was Slack. Is it possible that this user had the same thing happen to them? When I disable the watch unlocking, I can't make the password go anywhere but into the login screen (10.13.1 here with last weeks security update applied)
- geerlingguy 9y agoBecause of the short delay between waking the Mac and the display lighting up, I always either use spacebar or command key, or click the trackpad/mouse a couple times to wake. Return is a dangerous key!
- Dotnaught 9y agoLeft Slack open with focus, allowed MBP to sleep, woke with space bar, login field had focus, tried with closing lid and opening while Slack was open and focused, again password field functioned as it should, unable to reproduce, macOS 10.13.2
- fofolo 9y agoDifficult to reproduce, can be when we lock the session, close the macbook, plug a second screen and re-open. Or in another order. Personally I remember not having the focus on the password input by opening my MacBook onetime, I often plug and unplug screens
- lostlogin 9y agoI was in a huge lecture hall and the presentation from the head of school was going to talk. He plugged in, turned to look at the display from the projector and it hadn’t come up yet. He types in his username and password and stood there waiting. When the projector came to life he had typed it all into the username field. He fixed it up then displayed his desktop to us with all the pending final exam papers sitting there. No one in the hall showed any obvious sign of realising what had just occurred.
- djsumdog 9y agoI worked at an open source shop where almost everyone ran Linux and used IRC for chat. For a while I made the mistake of having the screen black time lower than the screensaver timeout, so I'd unlock my screen and see my password go out in IRC. I ended up changing my password to something that looked like a shell command.
- dwyerm 9y agoI worked in a mixed shop, and when my Linux box showed the BSOD screensaver, my Windows-aligned co-worker helpfully rebooted my machine for me.
- tachion 9y agoOh, wow - I've reported this problem along with na example exploit to Apple about 6-7 years ago. Never got any recognition for it, but It was fixed some time after that. It's quite sad to see old bugs getting new lives like that. For those interested, the sample exploitation that I've discovered was connecting any iPod/iPhone device to a OSX laptop while screen was locked was taking the focus away from login prompt 'into' the system, where iTunes was gaining it and from there it was just few OS level keyboard shortcuts from gaining network access to the system, while still locked: launch finder, go to tools folder, launch terminal, launch `nc` in the terminal to get the access via network. Lots of blind typing but it worked more times than not.
- zelos 9y agoI remember seeing something like this with an some version of 10.12 as well. Stupidly it didn't occur to me that it was a security issue.
- brazzledazzle 9y agoI've seen enough regressions with enterprise stuff that I've wondered what their testing looks like. Of course they've always neglected the enterprise so I gave them the benefit of the doubt about the OS as a whole but now I'm starting to wonder.
- yeukhon 9y ago> Oh, wow - I've reported this problem along with na example exploit to Apple about 6-7 years ago Any proofs? Perhaps you can demand a bounty payout or sue them ignoring!
- symlinkk 9y agoA similar thing happens to me sometimes with 1Password on the web. I'll click the extension's icon and type in my password and realize I'm typing it into a text box on the webpage. I've tried to reproduce it and I can't, so I have no idea what the issue is. It freaks me out though.
- lloydde 9y agoAlthough this bug still sucks, the class of problems of pasting passwords into chat may have a simple, worthwhile, and general solution. A colleague at a former company always changed the key bindings is his IRC/Jabber client to include a control key with Return for sending a message. Does Slack have this option?
- jerf 9y agoLock screens are harder than they first appear: www.jwz.org/xscreensaver/toolkits.html (Which, you'll note, mentions this exact failure case in the "Transfer Grabs?" section.) There's some X-specific stuff in there, but there's a lot of general issues in there, and with just a bit of imagination most or all of the X-specific issues can be seen as general issues as well.
- striking 9y agoN.B. jwz does not like being linked to from HN. Open the link in a new tab.
- drb91 9y agoWith treatement like that, I’d prefer to avoid this person and all their content.
- username223 9y agoYour loss. Jamie Zawinski probably helped write a lot of the software you're using right now, and has observed the internet almost since its birth.
- miranda_rights 9y agoDo you know why he has such an aversion to HN?
- username223 9y agoNo -- I don't know him personally -- but I would guess that he thinks it's a pile of amoral greed-heads and ignorant children.
- gaius 9y agoamoral greed-heads and ignorant children. Basically HN is him when he worked for Netscape and he doesn't like the reminder...
- malchow 9y agoNot to pile on, but my MBP (with "TouchBar" which will assuredly not exist in another year) is always in clamshell mode and connected to two external LG 4K displays. Whether, on which screen(s), or in what state the Mac wakes each morning is completely random. Sometimes it doesn't wake at all. Sometimes I have artifacts on one screen and a desktop on another screen. The sleep/wake sequence is a complete mess, and it doesn't surprise me that the focus might sometimes be on apps running in the user session behind the lock screen.
- jamesfmilne 9y agoI have a similar problem running my touchbar Macbook Pro in clamshell mode via a CalDigit USB-C dock. All sorts of issues with it discovering USB devices when you plug the hub in too.
- malchow 9y agoYes. One day a week my Logitech USB mouse is not recognized or powered by the MBP. Which day it will be is a crapshoot. If the Woodway treadmills at the Palo Alto Equinox had the same uptime as my Macbook Pro, I don't think certain Apple execs would be happy.
- bartvk 9y agoReally!? Me too. I have the USB discovery problem with two other hubs. It only recently started, maybe since 10.13.1 or so.
- AckSyn 9y agoI've seen that issue with LG displays at work, but when I get home and plug in the MBP to the setup there, (I have dual "Dell Ultra HD 4K Monitor P2415Q 24" displays on my 2017 15" Macbook Pro) there's never a problem. I'm inclined to believe it's the LG displays. Their washer/dryer appliances have some issues too, so I've learned to stay away from them.
- 1_2__4 9y agoLet's all sit and reflect for a moment that Apple was the first (and for a long time, the only) company that used to get sleep/wake "right".
- caiob 9y agoI may be wrong, but Slack might be hijacking the window order, there's def some monkey business going on there.
- oatmealsnap 9y agoNothing should be able to hack outside of of the lock screen. That should require some crazy special permissions.
- DannyBee 9y agoThe system allows things like key-triggered screen grabs during the login password window (found this out when my 1 year old hit a bunch of keys), which already seems like nonsense.
- yAnonymous 9y agoThis is really Slack's fault for not automatically turning the password into stars. IRC has done that for years!
- andr 9y agoCitation: http://bash.org/?244321 http://bash.org/?244321
- kuon 9y agoNow I feel old...
- j_s 9y agoSo weird to have seen this before it was flagged off the front page yesterday... pure coincidence? https://news.ycombinator.com/item?id=15876509 https://news.ycombinator.com/item?id=15876509
- godzillabrennus 9y agoAmazing. Reminds me of people being told in chat to hit F10 to enable cheats in Counterstrike Source. Half the gamers would exit immediately.
- lathiat 9y agoHave you seen the feature they added to the latest release of BitchX and irssi? Try it out: /disco party
- cjensen 9y agoI have slow Macs that I share with family. I've seen similar behavior when switching users. The full-screen password entry login comes up, but focus is still on regular apps.
- eamann 9y agoApple has a bug bounty program where they'll legitimately pay you to report bugs directly to them. What's with everyone reporting them to Twitter instead and forgoing the extra cash?
- zitterbewegung 9y agoSubmitting a bug bounty takes time. Also, informing people of security issues can be a virtue which is its own reward.
- gcb0 9y agothe bounties are low. and registering to those things require some loss of anonymity before you do get paid. those are users dogfooding a product they paid for. and probably well off already, so the twitter bragging rigths is more valuable than the loss of anonymity + $500.
- deleted 9y ago[deleted]
- bpicolo 9y agoThis doesn't seem like it would qualify under their categories. Not to mention, their bug bounty program info is nowhere to be found. I see tech sites reporting that they offer one but nothing on any apple site.
- AdmiralAsshat 9y agoThere's a case to be made for public shaming, sometimes. You're leaving it up to Apple to decide whether they want to pay you or not; they might deny the bounty for some reason, while still fixing the bug. Now you get nothing, in addition to having given Apple time to sweep the issue under the carpet and bury it under a change-log with language that heavily downplays the severity (e.g. "CVE - A buffer overflow could cause an application window behind the lockscreen to retain focus". Posting it on Twitter, however, draws attention to Apple's waning security practices and how such glaring holes manage to slip past their peer review. It sparks public outrage, and may serve as a wake-up call to the company.
- Fishkins 9y ago
- gcb0 9y agoon .2 already. Never had an unwatch to unlock. The ghost typing happened to me yesterday. I never found out what got my password. hopefully it wasn't slack. I assumed it just went to the "root window" (does quartz have the same concepts as X?) of the lock screen I usually press control key to wake up every computer (shift doesnt work on some). that one time I woke it up by tapping on the touchpad.
- kuon 9y agoI had this bug once a long, long, LONG time ago, since then my password is a sentence that's doesn't look like a password. Of course I'd still change it if it went out to slack :)
- j_s 9y agoI often wonder how many authentication log files contain passwords because people in a hurry append it to the username on accident (not visually confirming the Tab/Enter/switch to the password entry). This is also vaguely similar to the 'test SSL submit' security technique of first entering enough data into login forms to process a submission, and then entering real login info into the 'login failed' retry page after verifying SSL. This has lost some of its luster as non-SSL form submission has fallen out of wide usage.
- teekert 9y agoYeah, pretty sure mine is in clear text in some ssh auth.logs. Yeah yeah, I should use encryted keybased login (I try to mostly do it.)
- j_s 9y agoI typically require both when others are involved since proper key security can't be enforced (hardware 2FA is the dream). AuthenticationMethods requiring both wasn't availabe in OpenSSH prior to v6.2 (May 2013)[1] and I'm on Windows anyway so I went with https://www.bitvise.com/ssh-server https://www.bitvise.com/ssh-server. https://serverfault.com/a/562899 https://serverfault.com/a/562899
- hhbbhhg 9y ago> I often wonder how many authentication log files contain passwords because people in a hurry append it to the username on accident Is this why everyone does 2-step login on websites now?
- runjake 9y agoI have had this happen with 10.12 and 10.11 on rare occasions. To my knowledge, I'm not doing anything different on the occasions that it does happen. It wasn't Slack-specific as I've only started using Slack recently.
- happyrock 9y agoIt happened to me as well, but with HipChat.
- gonational 9y agoWith no disrespect to the developers at Apple, et al, each one of these problems that goes viral before reaching “proper” channels is a well-deserved slap in the face of these behemoth organizations. Perhaps, if the entire tech community regards Apple as a joke, they will start paying attention. “Responsible disclosure” is great stuff for creating a culture of free outsourcing of tech companies’ most imporant feature (security) to the same people that paid those companies thousands of dollars for that privilege.
- monochromatic 9y agoEspecially here, where it’s (probably?) not remotely exploitable.
- zamalek 9y ago> probably Show and focus a window when the user locks their machine.
- brazzledazzle 9y agoYeah. You can do keystroke logging without root but typing into password fields can't be intercepted. This would be a nice complement to that capability.
- throwawaymanbot 9y agoInterestingly, someone mentioned on twitter the same thing happening to them on ubuntu With slack. Would this be an issue with slack interjecting itself for key strokes?
- daveFNbuck 9y agoHow do you do that?
- fleitz 9y ago- (void) viewDidAppear{ [super viewDidAppear]; [self.passwordfield becomeFirstResponder]; }
- ebbv 9y agoThe quality of the software and the sacrifice of key functionality in the hardware (dropping of MagSafe, which was a huge differentiator, going to just USB-C ports which almost nothing supports, not even Apple's own in box phone chargers) demonstrates that Apple is purely a design house lately. It has completely faltered on the engineering side. Tim Cook is not an engineer and Jony Ive is not an engineer. There are engineers at the company but they don't seem to be getting a seat at the big table.
- ssijak 9y agoYeah, magsafe is paramount to doing professional work on a professional machine.
- bartvk 9y agoYou talk as though you're stating facts. However I very much like USB-C for the usual reasons. Of course it's in the early stages, but personally I hook up all my peripherals to my laptop with a single cable. Much convenience.
- rickyc091 9y agoDefinitely done that before. Sent my password through Messages to a friend. After that, I learned to keep the finder or a web browser as the thing in focus before I lock my computer.
- csomar 9y agoI'm really bothered. While I had relatively no issues with the fresh OS X update, I'm having a hard time with the iPhone 7 and the new iOS that is supposed to run their flagship device: iPhone 10. While most of the bugs have disappeared with the recent update, there are still some minor ones that really pisses me off: Screen freezing unresponsively for 30-60 seconds before things get back to control; and music playing randomly (happened a few times. Everything calm. Boom, music starts to play). I'm pretty sure this mess wasn't here before the update to iOS 11. Edit: Just found there is a new update. Let's see if they are getting their shit together this time.
- hashbig 9y agoWouldn't be surprised if it was intentional. Apple is known for planned obsolescence for their products, especially iPhones.
- AlexandrB 9y agoI hear this line a lot and yet iPhones get the latest iOS updates for many years after release while many Android phone are lucky to get 1 year of updates.
- hashbig 9y agoI would be much happier if Apple didn't "force" me to update my iPad with a pop up message every day. It was running smooth like butter, even with an older version of iOS.
- martinp 9y agoNot surprised by these bugs any more. The sheer amount of bugs in High Sierra is ridiculous, with the exception of the root password bug, I've personally experienced the following bugs with my Thunderbolt display: * In 10.13 or 10.13.1 the built-in web camera was broken. The video would freeze after a few seconds when attempting to use the camera in FaceTime. This was fixed in 10.13.2. * In 10.13.2 USB audio devices connected to the TB display no longer work properly. After playing audio through the device (USB DAC in my case) for 30-60 seconds, some sort of interference/electrical noise appears for 5-10 seconds every minute or so. I assume this has something to with "Improves compatibility with certain third-party USB audio devices." from the 10.13.2 release notes.
- sccxy 9y agoFor me it is impossible to update macOS too. App Store is not working. Downloading fix from website tells that my fusion drive is not compatible with this kind of install. Use App Store. I don't even have a fusion drive.
- k3a 9y agoWhy you are still using it then? Operating systems are very complicated beasts, none is perfect but I like Linux the most. There are issues too but I feel like I have more control over it.. Sometimes work reasons force people into Mac/Windows though... :(
- DoodleBuggy 9y agoI have ran into this before, figured it was a generic login bug. Now I wonder what/where my login credentials went. Lovely.
- noahdesu 9y agoLast week I was resizing a window in High Sierra, and I noticed that the Chrome app in the background was also scrolling. That was completely unexpected. It's long been the case that the window doesn't need to be on top for this behavior, but in this case it wasn't just a focus issue, it was that I was in resize mode. Completely jarring when it happened, but seems related.
- gaius 9y agoThis is why Windows NT ensures no user process can intercept Ctrl-Alt-Del.
- JdeBP 9y agoNo. It is nothing to do with secure attention. This is why Windows NT runs the log-on user interface, the screen saver, and the elevation consent UI on separate desktops that have restrictive ACLs disallowing interactive user processes from creating windows there.
- gaius 9y agoThe SAS is specifically so no one can hijack/spoof the password dialog. When you enter it you can be 100% certain you are talking to NT.
- kyberias 9y agoYou're kinda both right. But the focus-protection part has nothing to do with SAS.
- gaius 9y agoConsider https://superuser.com/a/61772 https://superuser.com/a/61772
- Someone1234 9y agoNot really sure what you think that adds. Nobody is denying that the "anti-hijacking" forcing of CTRL-ALT-Delete adds to security, what they're saying is that it has nothing to do with this topic. This topic is about keyboard input focus. In Windows, due to the process hierarchy the login UI isn't running in the same context as desktop applications, so stealing focus or focus drift couldn't occur.
- gaius 9y ago
- 05 9y agoSay what you want about Windows, but no amount of sneakery can steal input focus from Winlogon window station (yes, there's a separate kernel object for that in NT/Win32K).
- JdeBP 9y agoIt is the (secure) desktop, not the window station.
- zeep 9y agoI'm always worried about this too... sometimes my session doesn't lock because I was watching a video and I go ahead and type my password before looking when I come back (some websites log all keystrokes).
- y3sh 9y agoFWIW this is a known security bug at Apple. I filed a bug about similar behavior where you can see the desktop briefly without logging in. Apple marked it as a duplicate. https://imgur.com/YxXtU2y https://imgur.com/YxXtU2y Here are the steps to reproduce: - Start Mac - Login - Turn on Screen Lock: System Preferences > Security > General > Check "Require Password" and Select 5 Seconds. - Turn on Hot Corner Sleep Display: System Preferences > Mission Control > Hot Corners > Select upper left > Put Display to Sleep > Ok - Attach external monitor - Activate hot corner by dragging mouse to upper left corner of screen - Wait 6 seconds - Click the mouse to trigger waking the screen - See brief flash of the desktop without logging in!
- deleted 9y ago[deleted]
- Lxr 9y agoThe desktop flash happens regularly to me when simply attaching an external monitor to my closed locked machine.
- Anselmo321 9y agoI used to get the desktop flash reliably by simplistische disconnecting or reconnecting an external monitor. High Sierra fixed it.
- drunken-serval 9y agoJust FYI, this works on 10.10 (Mavericks).
- fny 9y agoI actually think I've experienced something similar across every OS I've ever used. With Linux distros I was always able to trigger it by opening and closing the lid a few times. With Windows, I don't remember the exact sequence or what version. Overall, there appears to be something funky with this overlay technique and how things are asynchronously rendered.
- VirtualAirwaves 9y agoWindows handles this nicely with User Account Control (UAC) and Secure Desktop mode. Many of OSX's problems come from trying to shoehorn security on top of operating system concepts that were developed in 1969.
- hhbbhhg 9y agoThis sort of shit wouldn’t fucking happen if they put the login/lock screen into its own separate and independent desktop like Windows does. When Windows is more secure than you, you have big problems. In case someone thinks desktop Linux is better, it’s not. It’s much worse: https://www.jwz.org/blog/2015/04/i-told-you-so-again/ https://www.jwz.org/blog/2015/04/i-told-you-so-again/
- veridies 9y agoFYI, that link now redirects to a somewhat NSFW imgur page mocking HN.
- k3a 9y agoIt is sad. Linux could be better if more people used it. Currently its use for desktop is relatively low. People tend to trust companies more so all they can do now is complain and email company's support department.
- abakker 9y agoSo, Apple has the most available cash resource of any company out there (or at least close to). Yet, bugs galore, and strange product decisions. The obvious conclusion is that their management is failing to staff accordingly to the work that needs to be done. This could be because they are not aware that work needs to be done, which means engineers are not telling them, or that the management is not succeeding in hiring enough people to do the jobs. My gut instinct says that a some former people at Apple used to do a lot of undocumented QA work and sanity checks, and that as the company has grown and changed, nobody picked up the slack when they left. Now, they'll have to go through a formal process of re-identifying QA steps that need to exist, and hiring against them. It's been a hell of a month for them, though.
- joeblau 9y agoI'm guessing that it's going to be pretty difficult to hire an engineer who is: - Very good - Wants to live near Palo Alto - Is able to live in the US - Wants to be subjected to Apple's privacy rules - Wants to work on fixing bugs instead of making new features In the software engineering game, money only goes so far.
- tracker1 9y agoI'm pretty sure you'd find a LOT of people to do that work for $300k/year... Apple has lots of money to go as far as they like.
- joeblau 9y agoYeah, but if you can make $300k a year, you're likely not dedicating your software engineering career to fixing bugs. Also, you can go a few miles south to Los Gatos and work at Netflix and make $400k/year.
- linkregister 9y ago$400k/year? is that for Principal Engineers and Directors? What would a senior eng make there?
- joefreeman 9y agoSounds like the assumption is that the lack of focus means that the first password got sent to Slack? But it seems more likely that it was the second entry of the password that was sent to Slack, and it was just that the keyboard input was being buffered? (So the first password-enter eventually got processed, and then the second one got processed but after unlock.)
- nerpderp83 9y agoThese lock screen issues go back further than 10.13, I believe it was 10.10 or 10.11 my child was able to bypass the lock screen by mashing on the keyboard while the screensaver was fading out the login dialog. I witnessed it. I was not able to reproduce it in 10-15 minutes of testing. She did NOT type in the password. Just banging on the keyboard, playing with the screensaver.
- drunken-serval 9y agoI have a computer on 10.10. Has this issue.
- wruza 9y agoI also typed my apple id password to my peer, not into chat, but into another mac in the same room. Mac keyboards can disconnect and connect to wrong devices if used with them once. That specific setting was: my keyboard was used to setup his mini, mini was turned off and on later. My keyboard, already properly reconnected to my mac at that time, disconnects on timeout (or for whatever reason it does that few times a day). Mini “grabs” my keyboard when it goes back on air. I wake my sleeping mac via trackpad and try to type my password into focused password field. Non-obviously, no characters appear on my screen.
- deleted 9y ago[deleted]
- suresk 9y agoThis has been a very sporadic issue that I've seen once or twice per year at most, for quite a while with OS X - somehow, another window is able to steal focus from the login screen. I've never been able to reproduce it reliably or find a common element in all of the times it has happened, but it definitely has happened to me and I've also seen co-workers dropping their login password in a chat window due to this. But it is pretty rare, so hard to pin down. I've also noticed another thing happening more lately - locking the screen, only to have it automatically unlock itself a second or two later. I always have to make sure it actually stays on the screensaver for a few seconds before I trust it will actually lock.
- polock 9y agoMicrosoft employee saide. "Same issue as with using windows 10 with multiple monitors/screens." https://us.teamblind.com/article/wtf-apple-uBXwbJMc https://us.teamblind.com/article/wtf-apple-uBXwbJMc