Achim Weber
2010-Aug-09 14:57 UTC
[Secure-testing-team] Bug#592364: [network-manager] Popup for PIN shows entered PIN in cleartext
Package: network-manager Version: 0.8.0.999-1 Severity: normal Tags: security X-Debbugs-CC: secure-testing-team at lists.alioth.debian.org Hi! The popup which asks for a PIN of a (UMTS-) modem has a cleartext field instead of a passwort textfield. This should be changed to a password field. Now when you are in a public place (like a train or a coffee bar) every one can see the entered PIN! In the connection configuration there is a password field with a checkbox "Show password" which is disabled by default. I don''t know if this problem exist in NM 0.8, but since the update to NM 0.8.0.999/0.8.1 this is a real problem, especially because of bug #591723 where this popup shows up everytime the modem is connected although the PIN is already specified in the connection config. best regards Achim