Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010 CFP

Linux Magazine is offering free booths for the CeBIT 2010 computer fair to selected open source projects. Apply Now!

  linux-magazine.com » Online » News » GNOME Cleartext Passwords: Bug or Feature?  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

GNOME Cleartext Passwords: Bug or Feature?

The current discussion in the Ubuntu forums is about a possible security hole in GNOME, specifically about GNOME registered users having their passwords appear as cleartext on the keyring. Not a bug, say its defenders, but the security concept behind the GNOME keyring.

In the discussion thread, the discoverer of the "blatant security flaw" gave an example of how it happens in Ubuntu 9.10. The user starts Ubuntu and registers on the desktop. The path through the Applications | Accessories | Passwords and Encryption Keyrings menus arrives at the keyring manager. Clicking on the Login folder shows the application processes and programs (including WLAN and mail accounts) and their respective passwords.

A right mouse click on an entry shows a context menu of properties, one of its tab being for keys. Clicking Password pops up a screen asking whether keyring access is allowed, for which no restrictions exist. The passphrase then appears and can be viewed as cleartext.

Critics of this approach provide a scenario whereby a profile owner has multiple users allowing access to the account. Operating in WLAN mode he wants to ensure that his keyring passphrase is secure. The suggestion is to further secure it through the user password so that guests need to know the profile owner's password before discovering what the keyring passphrases are. As it is, so goes the argument, users without much technical knowhow can easily steal the passphrases, so that additional password protection would deter "99% of potential identify thieves."

Defenders of the GNOME keyring strategy assure that only registered users have access to passphrases, the solution being to "lock your screen if you walk away." Defenders refer to the gnome-keyring security philosophy that suggests just that: locking the screen and creating guest logins. For those who still consider this a problem, so far no hard and fast solution exists. However, it is being actively discussed, among other places in the gnome-keyring mailing list.

(Kristian Kissling)

Comments

It is a massive hole

Grumbling Marmoset Nov 02, 2009 6:08pm GMT

It is an incredible, massive hole in security - anyone with physical access to the keyboard and display can reveal all passwords in plain text. I can think of many situations where "lock your screen" simply does not apply, because you are in a hurry, because you are forgetful, because you are socially engineered into leaving your screen unlocked.

There are many environments where this level of incompetent insecurity is simply unacceptable, where as a consequence Linux is unacceptable - including environments with a Clear Desk Policy which I have worked in.

Useless

Ian M. Nov 02, 2009 5:53pm GMT

Sounds like KWallet for GNOME.. and I'll remove the useless pile of rubbish as soon as I figure out how.

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
Ubuntu 8.10 Seeking Beta Testers
Ubuntu Developer Week: IRC Workshops
Canonical Now Hiring Designers and Usability Visionaries
Ubuntu 9.04 Enters Beta
License to Spy: Ubuntu Developer Week
From Mac to Linux: A Musician Convert
Live Streaming from ApacheCon Europe 2009

All about Apache in 19 talks

Watch 3 days full of Apache talks live from Amsterdam on March 25-27 in the convenience of your home or office. Topics are: Apache Hadoop, Tomcat for Developers and Administrators, HTTP Server Administration and much more.

Find out more

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]