2010-09-13 23:06:25 |
Alan Pope 🍺🐧🐱 🦄 |
bug |
|
|
added bug |
2010-09-13 23:06:25 |
Alan Pope 🍺🐧🐱 🦄 |
attachment added |
|
Screenshot-2.png https://bugs.edge.launchpad.net/bugs/637649/+attachment/1580322/+files/Screenshot-2.png |
|
2010-09-14 10:23:44 |
Matthew Paul Thomas |
bug task added |
|
software-center (Ubuntu) |
|
2010-09-14 10:28:10 |
Matthew Paul Thomas |
software-center (Ubuntu): importance |
Undecided |
Medium |
|
2010-09-14 10:28:10 |
Matthew Paul Thomas |
software-center (Ubuntu): status |
New |
Triaged |
|
2010-10-07 22:55:42 |
Thomas Horsten |
security vulnerability |
no |
yes |
|
2010-10-08 19:22:33 |
abubakar |
canonical-identity-provider: assignee |
|
abubakar (bakarms) |
|
2010-10-08 19:41:56 |
Omer Akram |
canonical-identity-provider: assignee |
abubakar (bakarms) |
Omer Akram (om26er) |
|
2010-10-08 19:42:16 |
Omer Akram |
canonical-identity-provider: assignee |
Omer Akram (om26er) |
|
|
2010-10-11 14:25:32 |
jhfhlkjlj |
bug |
|
|
added subscriber Chauncellor |
2010-10-16 16:05:23 |
Stuart Metcalfe |
canonical-identity-provider: status |
New |
Invalid |
|
2012-01-12 15:43:26 |
Anthony Lenton |
tags |
|
client-server |
|
2012-01-22 22:37:44 |
Matthew Paul Thomas |
software-center (Ubuntu): assignee |
|
Matthew Paul Thomas (mpt) |
|
2012-01-25 14:33:36 |
Matthew Paul Thomas |
tags |
client-server |
buy-software client-server |
|
2012-01-25 14:51:15 |
Matthew Paul Thomas |
tags |
buy-software client-server |
buying-software client-server |
|
2012-05-10 22:59:20 |
Matthew Paul Thomas |
software-center (Ubuntu): assignee |
Matthew Paul Thomas (mpt) |
|
|
2012-05-10 23:00:25 |
Matthew Paul Thomas |
description |
The singe sign on page which appears when I buy software in the Software Centre doesn't look secure. i can't see anything that indicates it's going over SSL. I'd be concerned about buying software from a store that doesn't use SSL for their logon screen. |
The singe sign on page which appears when I buy software in the Software Centre doesn't look secure. i can't see anything that indicates it's going over SSL. I'd be concerned about buying software from a store that doesn't use SSL for their logon screen.
<https://wiki.ubuntu.com/SoftwareCenter#security>: "The “View” menu should contain a “Security Info” item that is insensitive by default ... Whenever the page is encrypted and the certificate is okay, at the trailing end of the navigation bar should be a padlock icon with the label “Secure”, and the “Security Info” item should be sensitive. If you choose either of those, a “Security Info” window should open with text “The connection to the store is encrypted.” and information about the connection and certificate." |
|
2012-08-17 07:27:21 |
Matthew Paul Thomas |
bug task added |
|
rhythmbox (Ubuntu) |
|
2012-08-17 07:28:15 |
Matthew Paul Thomas |
description |
The singe sign on page which appears when I buy software in the Software Centre doesn't look secure. i can't see anything that indicates it's going over SSL. I'd be concerned about buying software from a store that doesn't use SSL for their logon screen.
<https://wiki.ubuntu.com/SoftwareCenter#security>: "The “View” menu should contain a “Security Info” item that is insensitive by default ... Whenever the page is encrypted and the certificate is okay, at the trailing end of the navigation bar should be a padlock icon with the label “Secure”, and the “Security Info” item should be sensitive. If you choose either of those, a “Security Info” window should open with text “The connection to the store is encrypted.” and information about the connection and certificate." |
When you buy software in Ubuntu Software Center, or music in Rhythmbox, there's no indication that the connection is secure. I'd be concerned about buying software from a store that doesn't use SSL for their logon screen.
<https://wiki.ubuntu.com/SoftwareCenter#security>: "The “View” menu should contain a “Security Info” item that is insensitive by default ... Whenever the page is encrypted and the certificate is okay, at the trailing end of the navigation bar should be a padlock icon with the label “Secure”, and the “Security Info” item should be sensitive. If you choose either of those, a “Security Info” window should open with text “The connection to the store is encrypted.” and information about the connection and certificate." |
|
2012-08-17 21:09:13 |
Jamie Strandboge |
rhythmbox (Ubuntu): status |
New |
Triaged |
|
2013-11-25 20:02:55 |
dobey |
bug task deleted |
canonical-identity-provider |
|
|