Language Selection

English French German Italian Portuguese Spanish

GNOME Keyring

Filed under
Software
Security

For the past week or so, people have been talking about a “security issue” in Seahorse. This sums up my opinion on the matter:

This isn't a security issue, and there is no good way to fix it.

A password managing daemon, such as GNOME Keyring, increases the security of stored passwords for the following reasons:

  • Passwords are stored in a database that uses real encryption, not just an obfuscation scheme
  • A single code base needs to be audited to make sure no vulnerabilities exist in the encryption algorithms that are being used
  • The database is protected by a password that is known only to the user who unlocks it
  • Since the database is encrypted, no other user or bootable CD can recover the stored passwords if the unlock password is not known

So, if GNOME Keyring increases the security of user credentials, why can you see your passwords exposed in plain text when you open Seahorse? Because you've unlocked the keyring using your login password.

Full Post




More in Tux Machines

And now for some good news... How open source triumphed over Microsoft Office in Italy

Microsoft Office may have a global monopoly, but one Italian region rejected it flat out. But, why? In the stunningly beautiful Italian region of Umbria, you'll feel more at home running open source software, rather than the clunky and expensive Microsoft Office suite. Read more

Red Hat, Chilean government hold talks on open source initiative

The head of Chilean regulator Pedro Huichalaf agreed to pass information regarding the benefits of open source software to the ministerial committee for digital development Read more

IT teams are choosing open source - but not just for the cost savings

IT decision makers are increasingly turning to open source over proprietary software because they believe it offers them better business continuity and control Read more

Patent Troll Kills Open Source Project On Speeding Up The Computation Of Erasure Codes

Via James Bessen, we learn of how a patent trolling operation by StreamScale has resulted in an open source project completely shutting down, despite the fact that the patent in question (US Patent 8,683,296 for an "Accelerated erasure coding system and method") is almost certainly ineligible for patent protection as an abstract idea, following the Supreme Court's Alice ruling and plenty of prior art. Erasure codes are used regularly today in cloud computing data storage and are considered to be rather important. Not surprisingly, companies and lawyers are starting to pop out of the woodwork to claim patents on key pieces. I won't pretend to understand the fundamental details of erasure codes, but the link above provides all the details. It goes through the specific claims in the patents, breaking down what they actually say (basically an erasure code on a computer using SIMD instructions), and how that's clearly an abstract idea and thus not patent-eligible. Read more