IM Account password unencrypted on gconf-editor

Bug #202576 reported by Mahdi
256
Affects Status Importance Assigned to Milestone
telepathy-mission-control (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Binary package hint: telepathy-core

On up-to-date hardy amd64:

If you register an account on empathy, the password is saved via gconf. Thus, if you open gconf-editor and browse to /apps/telepathy/mc/<protocol>/ and see the field "param-password", you can see your registered password in plain text, unencrypted!
This should REALLY be encrypted! Otherwise anyone with access to your gconf registry can get your gmail or hotmail passwords!
I tested with gtalk, jabber, msn and sip protocols. All of them have this issue.

Revision history for this message
Kees Cook (kees) wrote :

The passwords should really be stored via the gnome-keyring manager. As for privacy, gconf settings aren't visible to other users.

Changed in meta-telepathy:
importance: Undecided → Wishlist
status: New → Confirmed
Revision history for this message
Laurent Bigonville (bigon) wrote :

This bug belong to tp-mc and is fixed upstream AFAIK

Revision history for this message
Guillaume Desmottes (cassidy) wrote :

It's fixed in upstream and in PPA package.

Changed in telepathy-mission-control:
status: Confirmed → Fix Committed
Revision history for this message
Laurent Bigonville (bigon) wrote :

fixed in intrepid (4.65-2)

Changed in telepathy-mission-control:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.