[Pkg-utopia-maintainers] Bug#592364: [network-manager] Popup for PIN shows entered PIN in cleartext

Achim Weber dotzball at gmx.net
Mon Aug 9 14:57:16 UTC 2010


Package: network-manager
Version: 0.8.0.999-1
Severity: normal
Tags: security
X-Debbugs-CC: secure-testing-team at lists.alioth.debian.org


Hi!

The popup which asks for a PIN of a (UMTS-) modem has a cleartext field instead
of a passwort textfield. This should be changed to a password field. Now when
you are in a public place (like a train or a coffee bar) every one can see the
entered PIN! 
In the connection configuration there is a password field with a checkbox "Show
password" which is disabled by default.

I don't know if this problem exist in NM 0.8, but since the update to NM
0.8.0.999/0.8.1 this is a real problem, especially because of bug #591723 where
this popup shows up everytime the modem is connected although the PIN is
already specified in the connection config.

best regards
Achim





More information about the Pkg-utopia-maintainers mailing list