boot cryptsetup passphrase prompt echoes typed characters as stars

Bug #778659 reported by ilf
44
This bug affects 9 people
Affects Status Importance Assigned to Milestone
plymouth (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Binary package hint: plymouth

So bug 566818 is fixed and plymouth no longer causes the cryptsetup passphrase prompt during boot to repeat the prompt with every character typed.

It still echoes an asterisk for every character typed. I consider this a security issue, since this reveals on the screen how many characters the passphrase consists of.

sudo and cryptsetup (and many others) do not echo anything when typing in passphrases. This is a deliberate security feature. plymouth should respect this and also not echo enything after the prompt.

ilf (ilf)
visibility: private → public
Steve Langasek (vorlon)
security vulnerability: yes → no
toobuntu (toobuntu)
Changed in plymouth (Ubuntu):
status: New → Confirmed
Revision history for this message
Hans Zehntner (j50k) wrote :

Password length gets written and logged to tty7 on Ubuntu Server 11.04.
This is unacceptable, because everyone with physical access is able to read that.

papukaija (papukaija)
description: updated
Revision history for this message
tekstr1der (tekstr1der) wrote :

Any update on this? I'll be looking at an Ubuntu server setup going into 12.04 LTS and this needs to be resolved.

Other distros handle the cryptsetup passphrase properly.

Revision history for this message
ilf (ilf) wrote :

Nope, still the same on a freshly updated 11.10.

Revision history for this message
ilf (ilf) wrote :

OMFG. Updated another box.
It still displays a star for every character when unlocking the first (system) disk.
But it displays the plain passphrases for all my other disks after the first one!

Revision history for this message
ilf (ilf) wrote :

Can anyone else check this out please?
Then raise the Importance to Critical.

Revision history for this message
Cybjit (cybjit) wrote :

The plain echoing is reported as bug 876626

Revision history for this message
ilf (ilf) wrote :

What's the holdup here? Do you not think this is a bug?

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.