"setup-data.conf" is saved as plaintext

Bug #1802305 reported by Jeb E.
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Boxes
Confirmed
Undecided
auto-csoriano
gnome-boxes (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

gnome-boxes saves "setup-data.conf" and all it's containing info - such as usernames, passwords, and private license codes - as plaintext.

This can be considered a security risk and can allow leakage of such content much easier to get into the wrong hands.

File location: '/home/<username>/.config/gnome-boxes/unattended'

ProblemType: Bug
DistroRelease: Ubuntu 18.10
Package: gnome-boxes (not installed)
ProcVersionSignature: Ubuntu 4.18.0-10.11-lowlatency 4.18.12
Uname: Linux 4.18.0-10-lowlatency x86_64
ApportVersion: 2.20.10-0ubuntu13
Architecture: amd64
CurrentDesktop: ubuntu:GNOME
Date: Thu Nov 8 08:34:50 2018
InstallationDate: Installed on 2018-08-17 (83 days ago)
InstallationMedia: Ubuntu 18.04 LTS "Bionic Beaver" - Release amd64 (20180426)
ProcEnviron:
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: gnome-boxes
UpgradeStatus: Upgraded to cosmic on 2018-10-19 (19 days ago)

Revision history for this message
Jeb E. (jebeld17) wrote :
Changed in gnome-boxes (Ubuntu):
status: New → Confirmed
description: updated
information type: Private Security → Public Security
Jeb E. (jebeld17)
description: updated
Revision history for this message
Alex Murray (alexmurray) wrote :

Looks like upstream used to store the password as plaintext but changed this a while ago to instead store it in the keyring - https://github.com/GNOME/gnome-boxes/commit/ac552985647ebb6d7ee924cd77f0b93df44b4ff0

I suggest filing an issue directly upstream if you believe the current behaviour is not secure so that it can be discussed directly with the developers https://gitlab.gnome.org/GNOME/gnome-boxes/issues

Thanks

Revision history for this message
Jeb E. (jebeld17) wrote :

Bug report has been added to Gnome's official "Gitlab" bug tracker for "gnome-boxes.
https://gitlab.gnome.org/GNOME/gnome-boxes/issues/317

Revision history for this message
Jeb E. (jebeld17) wrote :

"auto-csoriano <email address hidden>" added to Launchpad bug report.

Changed in gnome-boxes:
status: New → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

  • auto-csoriano Edit

Bug watches keep track of this bug in other bug trackers.