Reported by tspivey on 2011-03-28 02:52
In secure mode, the logging level can be adjusted. This makes it possible to log
all keystrokes typed to the nvda.log file for that session.
The usefulness of this as an attack technique is questionable because the log file is only
readable by administrators, but the log is still being
written to disk, and could easily be read by a rescue system.
Would it be a large issue if logging was disabled in secure mode? If something
needed to be debugged on the secure desktop, the serviceDebug registry key could be set to disable secure mode.
Comment 1 by jteh on 2011-03-28 02:57
Milestone changed from None to 2011.2
Comment 2 by jteh on 2011-03-28 07:20
Milestone changed from 2011.2 to 2011.1.1
Comment 3 by jteh on 2011-03-29 08:56
Fixed in 0209c08.