Bug#807992: [OATH-Toolkit-help] Bug#807992: per user oath files

2016-08-01 Thread Antoine Beaupré
On 2016-03-05 15:01:39, Antoine Beaupré wrote: > On 2015-12-21 16:44:23, Ilkka Virta wrote: >> On 16.12. 15:44, Antoine Beaupré wrote: >>> On 2015-12-16 06:21:01, Ilkka Virta wrote: >>> Right, you are right of course. I do think it's critical to keep that >>> file from being readable from random

Bug#807992: [OATH-Toolkit-help] Bug#807992: per user oath files

2016-03-05 Thread Antoine Beaupré
On 2015-12-21 16:44:23, Ilkka Virta wrote: > On 16.12. 15:44, Antoine Beaupré wrote: >> On 2015-12-16 06:21:01, Ilkka Virta wrote: >> Right, you are right of course. I do think it's critical to keep that >> file from being readable from random apps. The format *is* also a little >> brittle so it

Bug#807992: [OATH-Toolkit-help] Bug#807992: per user oath files

2015-12-21 Thread Ilkka Virta
On 16.12. 15:44, Antoine Beaupré wrote: On 2015-12-16 06:21:01, Ilkka Virta wrote: Right, you are right of course. I do think it's critical to keep that file from being readable from random apps. The format *is* also a little brittle so it seems important to have standardized access as well...

Bug#807992: [OATH-Toolkit-help] Bug#807992: per user oath files

2015-12-16 Thread Antoine Beaupré
On 2015-12-16 06:21:01, Ilkka Virta wrote: > A problem with doing that, is that anything that runs with the user's > permissions could trivially read the secret key from the user's home > directory. With SSH keys it's not a problem, since they are _public_ > keys. Plus, a user could do

Bug#807992: [OATH-Toolkit-help] Bug#807992: per user oath files

2015-12-16 Thread Ilkka Virta
A problem with doing that, is that anything that runs with the user's permissions could trivially read the secret key from the user's home directory. With SSH keys it's not a problem, since they are _public_ keys. Plus, a user could do something stupid, like resetting the OTP counter on every