[Bug 1878115] Re: logged luks passwords

2020-05-15 Thread Zbigniew Jędrzejewski-Szmek
Oh, man. Once the password is written to a file on a real disk (/var/...), it should be considered compromised. Using shred or rm makes no guarantee that the bytes are removed from the device. In particular, it would be fairly trivial to do something like "grep 'merged config' /dev/sda" and chances

[Bug 1812316] Re: systemd: lack of seat verification in PAM module permits spoofing active session to polkit

2019-09-12 Thread Zbigniew Jędrzejewski-Szmek
Upstream fix: https://github.com/systemd/systemd/commit/83d4ab5533 (in systemd-242). -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1812316 Title: systemd: lack of seat verification in PAM mo