[security flaw] Ubuntu is a plain text offender



On Mon, May 23, 2011 14:50, Amedee Van Gasse wrote:

On your membership page, you can change various delivery options such
as your email address and whether you get digests or not. As a
reminder, your membership password is

*CENSORED*

Also, why does Canonical store the mailing list passwords in plain text? I
use lots of different passwords so it's not a big security problem for me.
But I still find this one of the biggest WTFs in the Mailman software.

I might even file a bug report. Or add to the already existing bug report:
https://bugs.launchpad.net/mailman/+bug/266821

I just added my comments to the bug report.

Next I'm going to submit Ubuntu to the website that showcases plain text
offenders: http://plaintextoffenders.com

Ubuntu should stop using an insecure version of Mailman. Now.


--
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-users



Relevant Pages

  • Re: [security flaw] Ubuntu is a plain text offender
    ... use lots of different passwords so it's not a big security problem for me. ... I might even file a bug report. ... Ubuntu should stop using an insecure version of Mailman. ... emailed to you I suggest you run your own mail server and require the smtp ...
    (Ubuntu)
  • Re: Dapper Drake verdict: It sucks
    ... I had to use the Ubuntu's packages, ... I really don't want to move this machine over to Debian as most ... all be my fault as I need to adjust sudo passwords or something ... Also reading the blogs about Debian developers, and Ubuntu seems to ...
    (Debian-User)
  • Re: trojan problem
    ... > assume an attack via ssh and a brute force hack, ... Under XP (not yet under Ubuntu because I don't know the tools yet) I'd ... passwords in a single AES-protected file that is in removable storage ... Getting infected by an open ssh, ...
    (Ubuntu)
  • security issues
    ... passwords in the installer log files. ... any local user could see the password of the first ... The updated packages remove the passwords and additionally make the ... I use ubuntu because it's "easy," not expecting ...
    (Ubuntu)
  • Re: To auto-login or to not auto-login?
    ... say I give a computer to a non-technical user willing to try Ubuntu. ... Should it be set to auto-login? ... of options, after hearing your recommendation. ... Users are paid to enter passwords; ...
    (Ubuntu)