Jamie Strandboge [2010-04-21 12:38 -0000]:
> Obviously we can do an SRU/security update after the fact, but this
> does, as Marc pointed out, leave a root escalation path for malware or
> applications with a security hole.

That's a good point. Now that upstream has replied and confirmed that
having the password in the keyring was an accident instead of a design
decision to make other keyrings work, I have a much better feeling
about this, so I'll do an upload to lucid and try to push it right
after RC.

-- 
the login password is stored in the user's keyring
https://bugs.launchpad.net/bugs/566046
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to