[Bug 296682] Re: tsclient stores user/password as clear text

2009-06-19 Thread Alex Howells
I've also noticed that the files are created with less than perfect
permissions:

-rw-r--r-- 1 ahowells ahowells 872 2009-06-19 20:38 last.tsc
-rw-r--r-- 1 ahowells ahowells   0 2009-06-19 20:29 mru.tsc

Perhaps it would be possible for them to start life as -rw--- or
something, as well?

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-04-16 Thread Kees Cook
** Changed in: tsclient (Ubuntu)
   Importance: Undecided => Wishlist

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
** Also affects: tsclient
   Importance: Undecided
   Status: New

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
Upstream bug:
http://sourceforge.net/tracker/?func=detail&aid=1889093&group_id=192483&atid=941574

Upstream feature request:
http://sourceforge.net/tracker/?func=detail&aid=1834829&group_id=192483&atid=941577

** Changed in: tsclient (Ubuntu)
   Status: New => Confirmed

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-12 Thread clovepower
Also, the very same data is stored under /home//.tsclient folder
in last.tsc and mru.tsc files.

So, credentials are stored in clear text even if user is not explicitly
saving an RDP file.

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-11 Thread Jamie Strandboge
** Visibility changed to: Public

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-11 Thread Jamie Strandboge
** Visibility changed to: Public

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-12 Thread clovepower
Also, the very same data is stored under /home//.tsclient folder
in last.tsc and mru.tsc files.

So, credentials are stored in clear text even if user is not explicitly
saving an RDP file.

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-06-19 Thread Alex Howells
I've also noticed that the files are created with less than perfect
permissions:

-rw-r--r-- 1 ahowells ahowells 872 2009-06-19 20:38 last.tsc
-rw-r--r-- 1 ahowells ahowells   0 2009-06-19 20:29 mru.tsc

Perhaps it would be possible for them to start life as -rw--- or
something, as well?

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
** Also affects: tsclient
   Importance: Undecided
   Status: New

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
Upstream bug:
http://sourceforge.net/tracker/?func=detail&aid=1889093&group_id=192483&atid=941574

Upstream feature request:
http://sourceforge.net/tracker/?func=detail&aid=1834829&group_id=192483&atid=941577

** Changed in: tsclient (Ubuntu)
   Status: New => Confirmed

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-04-16 Thread Kees Cook
** Changed in: tsclient (Ubuntu)
   Importance: Undecided => Wishlist

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-06-19 Thread Alex Howells
I've also noticed that the files are created with less than perfect
permissions:

-rw-r--r-- 1 ahowells ahowells 872 2009-06-19 20:38 last.tsc
-rw-r--r-- 1 ahowells ahowells   0 2009-06-19 20:29 mru.tsc

Perhaps it would be possible for them to start life as -rw--- or
something, as well?

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
** Also affects: tsclient
   Importance: Undecided
   Status: New

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
Upstream bug:
http://sourceforge.net/tracker/?func=detail&aid=1889093&group_id=192483&atid=941574

Upstream feature request:
http://sourceforge.net/tracker/?func=detail&aid=1834829&group_id=192483&atid=941577

** Changed in: tsclient (Ubuntu)
   Status: New => Confirmed

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-04-16 Thread Kees Cook
** Changed in: tsclient (Ubuntu)
   Importance: Undecided => Wishlist

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-12 Thread clovepower
Also, the very same data is stored under /home//.tsclient folder
in last.tsc and mru.tsc files.

So, credentials are stored in clear text even if user is not explicitly
saving an RDP file.

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-11 Thread Jamie Strandboge
** Visibility changed to: Public

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
** Also affects: tsclient
   Importance: Undecided
   Status: New

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
Upstream bug:
http://sourceforge.net/tracker/?func=detail&aid=1889093&group_id=192483&atid=941574

Upstream feature request:
http://sourceforge.net/tracker/?func=detail&aid=1834829&group_id=192483&atid=941577

** Changed in: tsclient (Ubuntu)
   Status: New => Confirmed

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-12 Thread clovepower
Also, the very same data is stored under /home//.tsclient folder
in last.tsc and mru.tsc files.

So, credentials are stored in clear text even if user is not explicitly
saving an RDP file.

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-11 Thread Jamie Strandboge
** Visibility changed to: Public

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-04-16 Thread Kees Cook
** Changed in: tsclient (Ubuntu)
   Importance: Undecided => Wishlist

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-06-19 Thread Alex Howells
I've also noticed that the files are created with less than perfect
permissions:

-rw-r--r-- 1 ahowells ahowells 872 2009-06-19 20:38 last.tsc
-rw-r--r-- 1 ahowells ahowells   0 2009-06-19 20:29 mru.tsc

Perhaps it would be possible for them to start life as -rw--- or
something, as well?

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-06-19 Thread Alex Howells
I've also noticed that the files are created with less than perfect
permissions:

-rw-r--r-- 1 ahowells ahowells 872 2009-06-19 20:38 last.tsc
-rw-r--r-- 1 ahowells ahowells   0 2009-06-19 20:29 mru.tsc

Perhaps it would be possible for them to start life as -rw--- or
something, as well?

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
** Also affects: tsclient
   Importance: Undecided
   Status: New

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
Upstream bug:
http://sourceforge.net/tracker/?func=detail&aid=1889093&group_id=192483&atid=941574

Upstream feature request:
http://sourceforge.net/tracker/?func=detail&aid=1834829&group_id=192483&atid=941577

** Changed in: tsclient (Ubuntu)
   Status: New => Confirmed

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-04-16 Thread Kees Cook
** Changed in: tsclient (Ubuntu)
   Importance: Undecided => Wishlist

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-11 Thread Jamie Strandboge
** Visibility changed to: Public

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-12 Thread clovepower
Also, the very same data is stored under /home//.tsclient folder
in last.tsc and mru.tsc files.

So, credentials are stored in clear text even if user is not explicitly
saving an RDP file.

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-06-19 Thread Alex Howells
I've also noticed that the files are created with less than perfect
permissions:

-rw-r--r-- 1 ahowells ahowells 872 2009-06-19 20:38 last.tsc
-rw-r--r-- 1 ahowells ahowells   0 2009-06-19 20:29 mru.tsc

Perhaps it would be possible for them to start life as -rw--- or
something, as well?

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-12 Thread clovepower
Also, the very same data is stored under /home//.tsclient folder
in last.tsc and mru.tsc files.

So, credentials are stored in clear text even if user is not explicitly
saving an RDP file.

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2008-11-11 Thread Jamie Strandboge
** Visibility changed to: Public

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
** Also affects: tsclient
   Importance: Undecided
   Status: New

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-03-24 Thread Marc Deslauriers
Upstream bug:
http://sourceforge.net/tracker/?func=detail&aid=1889093&group_id=192483&atid=941574

Upstream feature request:
http://sourceforge.net/tracker/?func=detail&aid=1834829&group_id=192483&atid=941577

** Changed in: tsclient (Ubuntu)
   Status: New => Confirmed

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-04-16 Thread Kees Cook
** Changed in: tsclient (Ubuntu)
   Importance: Undecided => Wishlist

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-08-26 Thread ap
I just discovered this security issue on my own after deciding to
inspect my "~/.tsclient/last.tsc" file and couldn't believe this hadn't
been reported before. So I decided to do a google search which lead me
here.

Guys, this is bad news!  As mentioned by clovepower the password is
stored *in the clear* even if the user doesn't save the connection
settings. All that it's required is that the user enters his/her
password on the tsclient window, as opposed to the remote server's login
screen. Plus, "~/.tsclient/last.tsc" has world-readable permissions (as
mentioned by Alex)!

I'm surprised this issue hasn't been fixed by now since it was first
reported back on 11th Nov 2008. That's more than 9 months ago! How come
this hasn't been fixed by now? Ubuntu Security Team? Shouldn't the
importance of this bug be changed from "Wishlist" to "Medium"?

For now, I guess the only protection against this issue is to NOT enter
passwords on the tsclient Logon Settings screen. Instead, users should
type their credentials on the *remote server*'s login screen.

$ grep -e username -e password\:b -e address -e domain ~/.tsclient/last.tsc
domain:s:test
full address:s:ts.domain.foo:3389
password:b:mysecretpass
username:s:ap

$ ls -l ~/.tsclient/last.tsc
-rw-r--r-- 1 ap ap 873 2009-08-26 17:46 /home/ap/.tsclient/last.tsc

$ lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:Ubuntu 8.04.3 LTS
Release:8.04
Codename:   hardy

$ apt-cache policy tsclient
tsclient:
  Installed: 0.150-1ubuntu1
  Candidate: 0.150-1ubuntu1
  Version table:
 *** 0.150-1ubuntu1 0
500 http://gb.archive.ubuntu.com hardy/main Packages
100 /var/lib/dpkg/status

** Attachment added: "tsclient Logon Settings screen"
   
http://launchpadlibrarian.net/30862514/Screenshot-Terminal%20Server%20Client.png

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-08-26 Thread Cyclops
While it's not using the keyring (which it should), I've added a chmod forcing 
0600.
http://tsclient.svn.sourceforge.net/viewvc/tsclient/trunk/src/rdpfile.c?r1=26&r2=105&pathrev=105

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-08-26 Thread Cyclops
** Changed in: tsclient
   Status: New => Fix Committed

** Changed in: tsclient
   Importance: Undecided => High

** Changed in: tsclient
   Importance: High => Critical

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-08-26 Thread ap
using the keyring would be ideal, but anything other than storing the
password in the clear would have been a security improvement IMHO.
Hashing the password with a installation-specific salt should be trivial
to implement for instance.

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-08-26 Thread Cyclops
hash+salt is for storing passwords you will authenticate against (like
/etc/shadow, for instance). In this case, it's the remote credentials so
you don't have to type them on each connection. If it was crypt+salted
how would the software know what the password is without showing it to
everyone anyways?

The final solution is to use the keyring. I will have to see how that is
done (or submit a patch *hint*hint*hint*) :)

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 296682] Re: tsclient stores user/password as clear text

2009-08-27 Thread ap
Cyclops: you're correct that if hashing is used, then the user would not
be able to save the password, and would have to retype it for each
connection as a hash is not reversible. So yeah, hashing would *not* be
a valid solution for users who would like to save their remote
connection passwords in order to avoid entering them upon every remote
logon.

-- 
tsclient stores user/password as clear text
https://bugs.launchpad.net/bugs/296682
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs