Comment 4 for bug 1780365

Revision history for this message
Seong-Joong Kim (sungjungk) wrote :

I know about that, but the problem is more serious than what I initially thought.
Existing issues have focused primarily on the behavior of seahorse and simply expect to prompt for a password before displaying a key’s plaintext password.
Moreover, countermeasures in Ubuntu Security FAQ is not appropriate for the problem and it doesn’t work like that.
The underlying problem has not been solved yet.

Instead, I would like to propose a different method by using access control scheme provided by DBus internal. Existing other services based on DBus are already taking advantage of the technique, as I mentioned above posting.

For your information, a similar issue of keychain in MAC OSX has been reported and already solved using access control technique (please check the related paper “Cracking App Isolation on Apple: Unauthorized Cross-App Resource Access on MAC OS~X and iOS, ACM CCS 2015).