all guides out there lead to configuration open to brute-force attacks

Bug #1490905 reported by maarten
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
google-authenticator (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

I posted an issue at Google Code about this package: https://github.com/google/google-authenticator/issues/514.
All the guides out there (e.g.: http://www.howtogeek.com/208205/how-to-use-two-factor-authentication-on-your-linux-desktop-with-google-authenticator/ and http://askubuntu.com/questions/193248/google-authenticator-for-desktop-lightdm-or-gdm-plugin) lead to configurations that leave your system wide open for brute force attacks on the first factor: the password. This is exactly what people expect to be solved with this package.

A possible solution could be to rename this package, which will invalidate all existing manuals, and to place a new and secure instruction on the ubuntu channels for the new package name.

tags: added: google-authenticator
tags: added: brute-force
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in google-authenticator (Ubuntu):
status: New → Confirmed
Revision history for this message
Jeremy Bícha (jbicha) wrote :

What exactly is the bug that needs fixing here?

Is there documentation in Ubuntu itself that is wrong?

If it's external documentation, then please report the issue to the publishers of that documentation, but that's not really an Ubuntu bug then.

Changed in google-authenticator (Ubuntu):
status: Confirmed → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for google-authenticator (Ubuntu) because there has been no activity for 60 days.]

Changed in google-authenticator (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.