[Bug 690514] New: pinentry-{gtk2,qt4} doesn't allow copy&paste
https://bugzilla.novell.com/show_bug.cgi?id=690514 https://bugzilla.novell.com/show_bug.cgi?id=690514#c0 Summary: pinentry-{gtk2,qt4} doesn't allow copy&paste Classification: openSUSE Product: openSUSE 11.4 Version: Final Platform: Other OS/Version: Other Status: NEW Severity: Major Priority: P5 - None Component: Other AssignedTo: puzel@novell.com ReportedBy: lnussel@novell.com QAContact: qa@suse.de Found By: --- Blocker: --- The graphical pinentry programs don't allow to paste a passphrase via middle mouse. I got a document symmetrically encrypted with a 64 byte random string. That's impossible to type in... -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690514
https://bugzilla.novell.com/show_bug.cgi?id=690514#c
Petr Uzel
https://bugzilla.novell.com/show_bug.cgi?id=690514
https://bugzilla.novell.com/show_bug.cgi?id=690514#c1
Petr Uzel
https://bugzilla.novell.com/show_bug.cgi?id=690514
https://bugzilla.novell.com/show_bug.cgi?id=690514#c2
Ludwig Nussel
https://bugzilla.novell.com/show_bug.cgi?id=690514
https://bugzilla.novell.com/show_bug.cgi?id=690514#c3
--- Comment #3 from Petr Uzel
I don't see any security gain from disallowing copy&paste. What's the threat this is supposed to protect against?
Originally, my impression was that even displaying the password on the screen and copying it to X clipboard might pose a security risk (yes, nothing pinentry could protect against anyway). OTOH, on second thought, if some process has access to X clipboard, it has probably also other ways of getting to the password and also inability to use 'too-long-to-type-in' passwords won't improve security. Just checked kdesu and gnomesu and both allow pasting. IOW, I'm convinced ;) -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=690514
https://bugzilla.novell.com/show_bug.cgi?id=690514#c5
Vitezslav Cizek
https://bugzilla.novell.com/show_bug.cgi?id=690514
https://bugzilla.novell.com/show_bug.cgi?id=690514#c6
--- Comment #6 from Bernhard Wiedemann
https://bugzilla.novell.com/show_bug.cgi?id=690514
https://bugzilla.novell.com/show_bug.cgi?id=690514#c7
Vitezslav Cizek
participants (1)
-
bugzilla_noreply@novell.com