kwalletmanager reasking for password for app

Bug #73386 reported by amichair
6
Affects Status Importance Assigned to Milestone
kdeutils (Ubuntu)
Invalid
Wishlist
Unassigned

Bug Description

Binary package hint: kwalletmanager

Whenever I boot into Kubuntu, KWalletManager prompts me to enter a password for KNetworkManager in order to connect to the Internet. In KDE Wallet configuration, 'knetworkmanager' appears under the 'kdewallet' wallet, with the policy 'Always Allow'. Doesn't this mean it's supposed to allow knetworkmanager access to the wallet without prompting me for the password after each boot? is this a bug or did I misunderstand this functionality? any way to get it to stop prompting after every boot and connect automatically?

Revision history for this message
Rob Hasselbaum (rhasselbaum) wrote :

Set the KWallet password to blank. You should no longer get prompted for it.

Revision history for this message
amichair (amichai2) wrote :

While this will probably work, it loses all security of the sensitive data stored in the wallet - anyone can access it anytime for any reason. The preferred solution (and from my basic understanding this is what I expected to happen) is that I can 'delegate' the authority to access the wallet to a particular application, which can then use it freely without prompting the logged on user for anything - any user can use the app even if he doesn't know the password, but he cannot access the data in the wallet itself or use it for any other purpose.

Revision history for this message
Rob Hasselbaum (rhasselbaum) wrote :

I don't think this is true, assuming file permissions are set appropriately on the password file(s). I think a security threat comes into play only if you walk away from a public terminal. But I could be misunderstanding how KWalletManager works.

Revision history for this message
amichair (amichai2) wrote :

Well I understand close to nothing about it :-)

But even if the solution is to leave the password blank, and the only security threat is the one you mention, I still think it's a good idea to add per-application priveleges as an enhancement - that's one less security threat to worry about.

Revision history for this message
Luka Renko (lure) wrote :

You might say that this is valid wishlist, but then you should submit it upstream as it is very unlikely that this will be added by Kubuntu developers.

Changed in kdeutils:
importance: Undecided → Wishlist
status: Unconfirmed → Confirmed
Revision history for this message
Jonathan Anderson (jonathan-anderson) wrote :

"Always allow" means that kwallet don't prompt you with "would you like to let knetworkmanager access your wallet".

The first time any app accesses the wallet, a password is required to decrypt the contents.

Changed in kdeutils:
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.