Comment 87 for bug 194472

Revision history for this message
Matthew Paul Thomas (mpt) wrote :

"2. has no significant security impact on desktop installs when the screensaver, policykit, gksu, and gdm (kdm?) all give feedback. As mentioned in comment #60, the asterisks are removed after pressing Enter, but it is recommended that this happens for all of gnome-terminal, konsole, xfce4-terminal and xterm (and any others people would like to test). We do not want visual feedback saved in scrollback or history."

Jamie, what about if sudo showed the asterisks while you were typing, but then deleted them the moment you pressed Enter? Then they wouldn't be in scrollback or history. Would that be acceptable on a server?