Bug 475071

Summary: Security Risk in Login to Fedora 9
Product: [Fedora] Fedora Reporter: basilicum <web02>
Component: gdmAssignee: jmccann
Status: CLOSED DUPLICATE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: low    
Version: 9CC: cschalle, jmccann, rstrode
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-12-08 08:25:06 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description basilicum 2008-12-07 11:02:20 UTC
User-Agent:       Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.1.18) Gecko/20081112 Fedora/1.1.13-1.fc9 SeaMonkey/1.1.13

In Fedora 9 the gnome login window shows a list of a set of users. This looks pretty, (you can I think put a photo of the person), but is in fact a high security risk.

The login consists of two things: the username and the password. The password is to be secret at all times. However, the username is half of the secret, if a hacker has the username, he/she can try to break the password. 

There for this login window has a high security risk in it. At least you should be able to switch the showing of the list of users off. 

In fedora 8, you could switch of this list of users, why has it disappeared ? It looks funny a list of photographs, but in many situations it is a security risk.

Reproducible: Always

Steps to Reproduce:
1.
2.
3.

Comment 1 Tomas Hoger 2008-12-08 08:25:06 UTC

*** This bug has been marked as a duplicate of bug 449728 ***