Upstream issue was closed "RESOLVED OBSOLETE" on 2011-04-04 due
to recent changes involving gio. Confirmed password not shown
when using Ubuntu 18.04 so marking "Fix Released" to close.


** Changed in: nautilus (Ubuntu)
       Status: Triaged => Fix Released

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to nautilus in Ubuntu.
https://bugs.launchpad.net/bugs/509272

Title:
  nautilus shows password in plaintext

Status in Nautilus:
  Expired
Status in nautilus package in Ubuntu:
  Fix Released

Bug description:
  Binary package hint: nautilus

  Recently, I needed to write a small script to connect to my home
  server via sftp through nautilus.  To my horror, I've discovered that
  when you connect via:

  nautilus "sftp://username:password@host/";

  the password is shown in plaintext in the breadcrumbs -- and the
  places menu, and the desktop!  I can think of no reason why this
  should be the desired behavior.  Indeed, when I connect via the
  "connect to server" feature, the password is correctly not displayed.
  Note that entering the password on the command line would not normally
  be a security vulnerability since it does not show up in ps and if run
  from a script will not show up in the history file either.

  Although not a security hole, this could be a serious security issue
  if it is not noticed by the user.

  I've attached a screenshot of the nautilus window breadcrumbs.  If you
  need it I can give a screenshot of the other areas where I noticed the
  password, but I think it should be easily reproducible.

  Please let me know if you need more info.

  ProblemType: Bug
  Architecture: amd64
  Date: Mon Jan 18 12:50:06 2010
  DistroRelease: Ubuntu 9.10
  ExecutablePath: /usr/bin/nautilus
  InstallationMedia: Ubuntu 9.10 "Karmic Koala" - Release amd64 (20091027)
  NonfreeKernelModules: fglrx
  Package: nautilus 1:2.28.1-0ubuntu3
  ProcEnviron:
   PATH=(custom, user)
   LANG=en_US.UTF-8
   SHELL=/bin/bash
  ProcVersionSignature: Ubuntu 2.6.31-17.54-generic
  SourcePackage: nautilus
  Uname: Linux 2.6.31-17-generic x86_64

To manage notifications about this bug go to:
https://bugs.launchpad.net/nautilus/+bug/509272/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to