[Trisquel-devel] Serious privacy issue: Gnome-shell auto answers audio/video calls

Anandawardhana anandawardhana at gmail.com
Mon Dec 16 16:20:27 CET 2013


Hello,
I am not a developer, but I would like to bring your attention to a
serious privacy issue I sumbled opon today:

Gnome-shell version provided with Trisquel 6, auto answers incoming audio and
video calls. It doesn't show any warning or notification for incoming call. It
simply starts transmitting audio/video from the computer that receives the call
without the consent of the recipient.

How to replicate the issue:

Distribution - Trisquel 6
GNOME 3.4.2 with Kernel 3.2.0-57-generic

1) Install gnome shell on Trisquel 6.
2) Add your xmpp/jabber/google account to the default IM client (empathy). This
starts operating in the background. Your status can be set from the desktop.
3) Log out from the desktop and log in. Your online status is now shown without
starting empathy.
4) Call yourself (call the account you added to empathy) from another computer,
another account.
5) Your desktop will auto-answer the audio/video call.

Please see the forum discussion
https://trisquel.info/en/forum/gnome-shell-privacy-issue-auto-answering-voice-and-video-calls

Trisquel bug report
https://trisquel.info/en/issues/10724

And GNOME bug report
https://bugzilla.gnome.org/show_bug.cgi?id=720525

I am told that this version of gnome-shell is no longer supported by
the upstream. So this needs to be fixed somewhere downstream. Thanks
very much for paying attention.

Best regards,
Anandawardhana


More information about the Trisquel-devel mailing list