Language Selection

English French German Italian Portuguese Spanish

GNOME Cleartext Passwords: Bug or Feature?

Filed under
Software
Security

The current discussion in the Ubuntu forums is about a possible security hole in GNOME, specifically about GNOME registered users having their passwords appear as cleartext on the keyring. Not a bug, say its defenders, but the security concept behind the GNOME keyring.

In the discussion thread, the discoverer of the "blatant security flaw" gave an example of how it happens in Ubuntu 9.10. The user starts Ubuntu and registers on the desktop. The path through the Applications | Accessories | Passwords and Encryption Keyrings menus arrives at the keyring manager. Clicking on the Login folder shows the application processes and programs (including WLAN and mail accounts) and their respective passwords.

A right mouse click on an entry shows a context menu of properties, one of its tab being for keys. Clicking Password pops up a screen asking whether keyring access is allowed, for which no restrictions exist. The passphrase then appears and can be viewed as cleartext.

Rest Here




More in Tux Machines

Today in Techrights

Edubuntu Vs UberStudent: Return To College With The Best Linux Distro

Importantly, there are a handful of programs that are on Edubuntu that UberStudent doesn’t have, such as KAlgebra, Kazium, KGeography, and Marble. Instead, UberStudent has a smaller collection of applications but it does include some useful items when it comes to writing papers that Edubuntu does not have. So ultimately, Edubuntu includes more programs that are information-heavy, while UberStudent includes more tools that can aid students in their studies but doesn’t directly give them any sort of information. Read more

Zotac Nvidia Jetson TK1 review

The Jetson TK1, Nvidia’s first development board to be marketed at the general public, has taken a circuitous route to our shores. Unveiled at the company’s Graphics Technology Conference earlier this year, the board launched in the US at a headline-grabbing price of $192 but its international release was hampered by export regulations. Zotac, already an Nvidia partner for its graphics hardware, volunteered to sort things out and has partnered with Maplin to bring the board to the UK. In doing so, however, the price has become a little muddled. $192 – a clever dollar per GPU core – has become £199.99. Compared to Maplin’s other single-board computer, the sub-£30 Raspberry Pi, it’s a high-end item that could find itself priced out of the reach of the company’s usual customers. Read more

New Human Interface Guidelines for GNOME and GTK+

I’ve recently been hard at work on a new and updated version of the GNOME Human Interface Guidelines, and am pleased to announce that this will be ready for the upcoming 3.14 release. Over recent years, application design has evolved a huge amount. The web and native applications have become increasingly similar, and new design patterns have become the norm. During that period, those of us in the GNOME Design Team have worked with developers to expand the range of GTK+’s capabilities, and the result is a much more modern toolkit. Read more