Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't know... we've generally used suid binaries for this in the past? I suppose the display server will run as root, so the sane approach is to add a screenshot api, possibly writing the screenshot to a file/folder/socket with special permissions? ("special" because the gist here seems to be a wish to limit capabilities more finely than traditional unix user/group/others -- after all the user has access to the whole desktop (say with a digital camera) -- so the goal here is apparently to limit which applications can access other applications. At any rate, root should be able to read all process' memory, so taking a screenshot shouldn't be a problem... (I'm not saying take a screenshot by reading video memory, just that the level of access is equivalent).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: