Password stored in plain text

Bug #1035277 reported by RobinJ
262
This bug affects 2 people
Affects Status Importance Assigned to Milestone
GWoffice
Fix Committed
Undecided
Unassigned

Bug Description

If you check "Save password", it stores the username and password in a plain text file called ~/.local/share/gwoffice/auth.

RobinJ (robinj)
visibility: private → public
Revision history for this message
Tom Beckmann (tombeckmann) wrote :

There's a tooltip warning you about this.
Right now I'm hoping to be able to drop client login completely soon and replace it with gnome-online-accounts. The code is already there, it just needs a newer version. I really hope in 12.10 everything will work.

Revision history for this message
RobinJ (robinj) wrote :

A tooltip is easily missed. I think, if you can't release a quick fix for Gnome Keyring or something, that at least there should be a clear warning saying that the Google account data is stored in plain text.

Revision history for this message
Tom Beckmann (tombeckmann) wrote :

Took me a while to find the time, but now you got your password securely in the gnome keyring. The old password file should automatically be deleted on next launch.

Changed in gwoffice:
status: New → Fix Committed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.