[Bug 732740] New: ssh stores password permanently by default under GNOME
https://bugzilla.novell.com/show_bug.cgi?id=732740 https://bugzilla.novell.com/show_bug.cgi?id=732740#c0 Summary: ssh stores password permanently by default under GNOME Classification: openSUSE Product: openSUSE 12.1 Version: Final Platform: Other OS/Version: Other Status: NEW Severity: Major Priority: P5 - None Component: GNOME AssignedTo: bnc-team-gnome@forge.provo.novell.com ReportedBy: aj@suse.com QAContact: qa@suse.de CC: security-team@suse.de Found By: Product Management Blocker: --- From https://plus.google.com/u/0/116897159250746362191/posts/34EeVTd6D47 "my biggest concern right now is the ssh-agent dialog. Every time I start an ssh connection the agent defaults to simply remember the passphrase permanently. That is not a smart idea as there are known attacks on the agent. With other similar dialogs (like unlocking your keyring) once you switch to "remember for 1 minute" that's the default the next time you use it. Not so with ssh passphrases." "Gnome - so no, I'm not sure it's the agent. A quick ps shows neither the agent nor a seahorse process... :-(" -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=732740 https://bugzilla.novell.com/show_bug.cgi?id=732740#c1 Vincent Untz <vuntz@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO InfoProvider| |aj@suse.com --- Comment #1 from Vincent Untz <vuntz@suse.com> 2011-12-07 09:02:07 UTC --- So it's unclear which dialog this is -- knowing how to reach it would help. FWIW, the dialog I'm aware of has the default of remembering the password until you log out. Which means the password is kept in secure memory. Is there an issue with that? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=732740 https://bugzilla.novell.com/show_bug.cgi?id=732740#c2 --- Comment #2 from Andreas Jaeger <aj@suse.com> 2011-12-07 09:37:08 UTC --- Let me ask on google+... Andreas -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=732740 https://bugzilla.novell.com/show_bug.cgi?id=732740#c3 Dirk Hohndel <Dirk.Hohndel@intel.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |Dirk.Hohndel@intel.com --- Comment #3 from Dirk Hohndel <Dirk.Hohndel@intel.com> 2011-12-07 18:07:09 UTC --- Yes, the default is to remember the passphrase until you log out. And that's the problem. The dialog should remember what I picked last time. For example, I always want it to forget my passphrase after 1 minute - so now I have to click on options, pick forget after 1 minute and then ok /every/single/time/ I connect via ssh. The keyring used by chrome for passwords does just that - it remembers what I picked last time. The ssh-agent (or whatever it is that creates that dialog every time I connect via ssh) doesn't remember what I picked last time and instead always defaults to remember the passphrase until log out - and that's not acceptable for me. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=732740 https://bugzilla.novell.com/show_bug.cgi?id=732740#c4 Dirk Hohndel <Dirk.Hohndel@intel.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |NEW InfoProvider|aj@suse.com | --- Comment #4 from Dirk Hohndel <Dirk.Hohndel@intel.com> 2011-12-07 18:08:42 UTC --- BTW: those two dialogs look identical to me (or very very similar) - that makes it even more annoying that one behaves the right way and the other one doesn't. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com