nm-applet G3 modem pin entry is visible

Bug #296741 reported by LimCore
272
This bug affects 3 people
Affects Status Importance Assigned to Milestone
network-manager (Ubuntu)
Fix Released
High
Jamie Strandboge

Bug Description

When using nm-applet and G3 modem - I am asked for a PIN.

The PIN entry box shows the PIN on screen.

So, if I'm using G3 modem outside of my home (which is like, the point of it) then anyone can easly look over my shoulder to steal it (and grabbing g3 modem card is not that hard, then just enter my PIN and use my card...)

Combined with gnome-keyring (bug#296736 and/or bug#125075) I have to enter PIN each time so this is really bad.

Please make it show starred-out password.

If possible, add an [ ] show password option, same as it is for wifi passwords.

by the way:

------------------------
Also PLEASE (later?) make the dialog auto-check was the same PIN just entered - to avoid asking g3 modem hardware for the same bad pin that would easily lead to SIM card lock-out.

Example, pin is 1234
BAD:
- guy enters "1235" (typo) but sees ****
- guy enters "4321" (he thinks it was the other way around)
- guy enters "4321" again - he wonders if he did a typo in "4321"
SIM card locks self.

GOOD solution:
- guy enters "1235" (typo) but sees ****
- guy enters "4321" (he thinks it was the other way around)
- guy enters "4321" and PIN entry menu warns "You already tried this PIN during this session (in last minutes) and it did not work. Your probably want to try another PIN" [enter another pin] [re-send again the wrong pin (can lock card!)]
so guy chooses to try another pin, tries "1234" (no typo this time) and it works

LimCore (limcore)
description: updated
Revision history for this message
Kees Cook (kees) wrote :

Alexander, can you confirm this report? I do not have the hardware to validate it.

Changed in network-manager (Ubuntu):
assignee: nobody → asac
status: New → Incomplete
Revision history for this message
Alexander Sack (asac) wrote :

definitly was an issue once. I have to check whether its still an issue in latest NM.

Changed in network-manager (Ubuntu):
importance: Undecided → High
status: Incomplete → Triaged
Revision history for this message
Wolfgang Kufner (wolfgangkufner) wrote :

Just tested in lucid alpha-2 (aka 20100113) 64 bit iso loopback booted from hd via grub2:
The pin entry is still always visible.
And btw. it insist on exactly 4 digits, which bug 318265 seems to indicate might not be right for some people.

Revision history for this message
Jeffrey Ratcliffe (jeffreyratcliffe) wrote :

For me, there is an option to display the PIN or not - but since maverick, I also have the regression that it now asks me for the PIN every time I connect. With lucid, I was able to set it up once and forget about it.

Martin Pitt (pitti)
Changed in network-manager (Ubuntu):
assignee: Alexander Sack (asac) → nobody
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Based on comment #4, this sounds like it might be fixed in 11.04 (well, 10.10 but there seemed to be other problems there). Can someone test and report back?

Changed in network-manager (Ubuntu):
assignee: nobody → Jamie Strandboge (jdstrand)
status: Triaged → Incomplete
Revision history for this message
Sebastian Bator (eremit7) wrote :

Fixed, on standard the numbers are replaced by dots and there is an checkbox to show PIN.

Eremit

Changed in network-manager (Ubuntu):
status: Incomplete → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.