Each time when I’m entering my passphrase in pinentry-gtk-2
, every other X11 app may sniff it, as seen in
$ xinput test-xi2
running in the background.
What can be done about it?
Or do I have to trust hundreds of different processes running under my account(*) to not X11-sniff my passphrase when I’m typing it and not send my ~/.gnupg/
directory along with it over the internet to some adversary?
(*) Here, I’m not considering an almost-hardware keylogger running as root
very close to the kernel, as not much can be done about that. I’m talking regular, user-land applications, like closed-source Skype or Insync.