[Pkg-kde-extras] Bug#806500: quassel-client: Client configuration is world readable and contains password in plain text

Diederik de Haas didi.debian at cknow.org
Sat Nov 28 21:32:09 UTC 2015


On Sunday 29 November 2015 00:24:15 Boris Pek wrote:
> This should be enough I think:
> > drwxr-x--- 68 diederik diederik 12288 Nov 28 17:59 ../
> 
> Try something like this:
> $ LC_ALL=C su another-user -c 'ls -alp /home/diederik/.config'
> Password: 
> ls: cannot access /home/diederik/.config: Permission denied

Indeed. Phew :-)
diederik at bagend:~$ LC_ALL=C su quassel-test -c 'ls -alp /home/diederik/.config'
Password: 
ls: cannot access /home/diederik/.config: Permission denied

Sorry for the noise.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.alioth.debian.org/pipermail/pkg-kde-extras/attachments/20151128/9c894bf2/attachment.sig>


More information about the pkg-kde-extras mailing list