Bug#943716: systemd: generates a directory name with the /etc/machine-id value, which is confidential

2019-10-29 Thread Michael Biebl
Am 29.10.2019 um 08:21 schrieb Michael Biebl: > Am 29.10.2019 um 02:25 schrieb Vincent Lefevre: > >> Note also that the same paragraph recommends to use a hash as a >> stable unique identifier. But since this is meant to be stable >> and unique, this would also allow the machine to be tracked if

Bug#943716: systemd: generates a directory name with the /etc/machine-id value, which is confidential

2019-10-29 Thread Michael Biebl
Am 29.10.2019 um 02:25 schrieb Vincent Lefevre: > Note also that the same paragraph recommends to use a hash as a > stable unique identifier. But since this is meant to be stable > and unique, this would also allow the machine to be tracked if > such a hash is exposed on the network. So the

Bug#943716: systemd: generates a directory name with the /etc/machine-id value, which is confidential

2019-10-28 Thread Vincent Lefevre
On 2019-10-28 23:22:54 +0100, Michael Biebl wrote: > I don't see a problem with /etc/machine-id being word-readable, I don't > see a problem either with the journal directory containing the > machine-id. If someone posts the id to a forum, I don't consider this > problematic either. > > The man

Bug#943716: systemd: generates a directory name with the /etc/machine-id value, which is confidential

2019-10-28 Thread Michael Biebl
Control: tags -1 + moreinfo Am 28.10.19 um 15:23 schrieb Vincent Lefevre: > Package: systemd > Version: 242-7 > Severity: important > Tags: security > > systemd generates a directory name under /var/log/journal with > the /etc/machine-id value, which is confidential according to > the

Processed: Re: Bug#943716: systemd: generates a directory name with the /etc/machine-id value, which is confidential

2019-10-28 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + moreinfo Bug #943716 [systemd] systemd: generates a directory name with the /etc/machine-id value, which is confidential Added tag(s) moreinfo. -- 943716: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=943716 Debian Bug Tracking System Contact

Bug#943716: systemd: generates a directory name with the /etc/machine-id value, which is confidential

2019-10-28 Thread Vincent Lefevre
Package: systemd Version: 242-7 Severity: important Tags: security systemd generates a directory name under /var/log/journal with the /etc/machine-id value, which is confidential according to the machine-id(5) man page: This ID uniquely identifies the host. It should be considered