Re: 'Big Honking Security Hole' or something else?



On 10/17/2010 08:01 PM, Anthony Papillion wrote:
So, tonight I've been poking around my system and was looking around in
the Password and Encryption Keys application. I've stored a few website
logins and I notice they are sitting there IN PLAIN TEXT and very readable!

While I grant that accessing this information would probably require
physical access to the machine (though, maybe, SSH would allow access to
it too), isn't this a problem? The fact that usernames and passwords
are just sitting there in clear text?

Is there something I'm not understanding?

Obviously, this is pretty damn broad of a statement. How about you give
us more information. How were you viewing them? Where they stored in
the default keyring (which is unlocked when you login ~ if you login
with a password and not auto login)

This is operator malfunction I'm assuming, not system malfunction, but
you need to be less broad and more elaborative so we can better help you
and come to a real conclusion.

--
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-users



Relevant Pages

  • Re: Big Honking Security Hole or something else?
    ... logins and I notice they are sitting there IN PLAIN TEXT and very readable! ... Indeed, if you go to System> Preferences> Passwords & Encryption Keys, ... Strong login password, logging out ...
    (Ubuntu)
  • Re: Big Honking Security Hole or something else?
    ... logins and I notice they are sitting there IN PLAIN TEXT and very readable! ... Change the keyring password to be something separate from the login ...
    (Ubuntu)
  • Re: phishing attacks -- where to look first?
    ... When I find myself sitting at the ... console, what's the first thing I do? ... Login as root, run a find for ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Big Honking Security Hole or something else?
    ... logins and I notice they are sitting there IN PLAIN TEXT and very readable! ... physical access to the machine (though, maybe, SSH would allow access to ... the default keyring (which is unlocked when you login ~ if you login ... This is operator malfunction I'm assuming, not system malfunction, but ...
    (Ubuntu)
  • Re: local admin account password
    ... There is no physical access so that is already taken care of. ... the central DB has the infdo to login with so just a matter of querying it ... > Law #3: If a bad guy has unrestricted physical access to your computer, ... A machine is only as secure as the administrator is trustworthy. ...
    (Focus-Microsoft)