Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Password and Keys Security Issue?

  1. #1
    Join Date
    Apr 2008
    Beans
    490
    Distro
    Ubuntu 12.04 Precise Pangolin

    Password and Keys Security Issue?

    In 11.10, when you go to Passwords and Keys the default setting allows you to access passwords.

    I would think by default you should be prompted for your password when opening Passwords and Keys. If I let a friend on my computer they could go straight to Passwords and Keys to access my passwords.

    This seems like a security risk to me. Am I right or am I missing something?
    |

  2. #2
    Join Date
    Sep 2011
    Beans
    1,531

    Re: Password and Keys Security Issue?

    You could let your friend use a "guest" account instead of your account. I believe it's limited and wouldn't be able to see the passwords & keys (but you should check to be certain).

  3. #3
    Join Date
    Apr 2008
    Beans
    490
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Password and Keys Security Issue?

    Using the Guest account is an option to avoid this issue, but that is not my point.

    This is a security risk! Anybody stepping away from their computer for a minute is vulnerable. Somebody can access your passwords in under a minute! You should be prompted for your password first.

    This is a serious security risk unless I am missing something.
    |

  4. #4
    Join Date
    Sep 2011
    Beans
    1,531

    Re: Password and Keys Security Issue?

    This discussion has actually come up several times. See this thread for details

    http://ubuntuforums.org/showthread.php?t=1931670

    But the crux of the matter is physical access is root access.

  5. #5
    Join Date
    Jun 2011
    Location
    The Shadow Gallery
    Beans
    6,744

    Re: Password and Keys Security Issue?

    Quote Originally Posted by spikoley View Post
    Using the Guest account is an option to avoid this issue, but that is not my point.

    This is a security risk! Anybody stepping away from their computer for a minute is vulnerable. Somebody can access your passwords in under a minute! You should be prompted for your password first.

    This is a serious security risk unless I am missing something.
    the security issue is you letting someone use your account or not securing your machine when away from it.

    Physical access is root access

    This is all security basics and common sense


    Cheers
    Backtrack - Giving machine guns to monkeys since 2006
    Kali-Linux - Adding a grenade launcher to the machine guns since 2013

  6. #6
    Join Date
    Apr 2008
    Beans
    490
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Password and Keys Security Issue?

    Quote Originally Posted by Ms. Daisy View Post
    This discussion has actually come up several times. See this thread for details

    http://ubuntuforums.org/showthread.php?t=1931670

    But the crux of the matter is physical access is root access.
    That is a different issue. I would agree with you if this issue was the same as the one in the link.

    Quote Originally Posted by haqking View Post
    the security issue is you letting someone use your account or not securing your machine when away from it.

    Physical access is root access

    This is all security basics and common sense


    Cheers
    Then why even have sudo? That line of think is an argument against sudo. This is a sudo issue.

    Do you think having a lock on User Accounts is a bad idea? Currently when you go into User Accounts it requires a password to unlock it. This issue is exactly the same. My argument is Passwords and Keys should be treated the same as User Accounts when it comes to security.
    Last edited by spikoley; March 18th, 2012 at 11:15 PM.
    |

  7. #7
    Join Date
    Sep 2011
    Beans
    1,531

    Re: Password and Keys Security Issue?

    If it's a serious security risk then you have the option to: 1) log out, 2) hibernate/suspend and require a password to resume. 3) Let a friend use guest and he won't have access to password files.

    When you're logged into your machine and you simply walk away leaving it running, I don't understand how you could secure the entire system- not just the password file.

  8. #8
    Join Date
    Apr 2008
    Beans
    490
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Password and Keys Security Issue?

    Quote Originally Posted by Ms. Daisy View Post
    If it's a serious security risk then you have the option to: 1) log out, 2) hibernate/suspend and require a password to resume. 3) Let a friend use guest and he won't have access to password files.

    When you're logged into your machine and you simply walk away leaving it running, I don't understand how you could secure the entire system- not just the password file.
    Then why have a lock on User Accounts? It makes no sense to have a lock on User Accounts and not Passwords and Keys. Shouldn't Ubuntu at least be consistent on how it treats similar applications?
    |

  9. #9
    Join Date
    Jun 2011
    Location
    The Shadow Gallery
    Beans
    6,744

    Re: Password and Keys Security Issue?

    Quote Originally Posted by spikoley View Post
    Then why have a lock on User Accounts? It makes no sense to have a lock on User Accounts and not Passwords and Keys. Shouldn't Ubuntu at least be consistent on how it treats similar applications?
    it is not Ubuntu's application.

    it is seahorse/GNU privacy guard

    and if you give your car keys to your friend and they crash your car is it then the car manufacturers fault that the car was allowed to be driven by the person with the keys ? or yours for giving the keys to someone ?

    Physical access is root access.

    Do you want a password prompt for every action ? or are you happy to allow your friend to access your documents, spreadsheets, emails but just not your passwords ? after all why do they need your passwords ? you have given them access to everything anyways

    Peace
    Backtrack - Giving machine guns to monkeys since 2006
    Kali-Linux - Adding a grenade launcher to the machine guns since 2013

  10. #10
    Join Date
    Apr 2008
    Beans
    490
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Password and Keys Security Issue?

    So why have sudo or a lock on any application? I've always thought it was there for security.
    |

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •