Printers should not be auto-added without permission from user

Bug #1716013 reported by Greg Williams
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-settings-daemon (Ubuntu)
Confirmed
Low
Unassigned

Bug Description

If Ubuntu 17.04 or 17.10 connects to a network that has a printer, a dialog pops open telling me so-and-so printer has been added. What the heck?

First, why is the user not asked whether to add the printer or not?

Second, auto-adding devices from a network is bad security practice. What if it's a hostile network? It is well established that printers are a common attack vector on networks. Ubuntu's auto-adding printers is the kind of thing that should not be happening by default without some kind of dialog that asks for permission to add said printer. If this is not addressed, it's only a matter of time before this leads to a CVE for Ubuntu.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Can I make this bug public?

Revision history for this message
Greg Williams (greg2lapa) wrote :

I didn't make it private intentionally. The software seems to make it private by default when Security is checked. I see no reason why this shouldn't be public.

information type: Private Security → Public Security
Revision history for this message
Sebastien Bacher (seb128) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. The issue you are reporting is an upstream one and it would be nice if somebody having it could send the bug to the developers of the software by following the instructions at https://wiki.ubuntu.com/Bugs/Upstream/GNOME. If you have done so, please tell us the number of the upstream bug (or the link), so we can add a bugwatch that will inform us about its status. Thanks in advance.

Changed in gnome-settings-daemon (Ubuntu):
importance: Undecided → Low
Changed in gnome-settings-daemon (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.