Bug 475071 - Security Risk in Login to Fedora 9
Summary: Security Risk in Login to Fedora 9
Keywords:
Status: CLOSED DUPLICATE of bug 449728
Alias: None
Product: Fedora
Classification: Fedora
Component: gdm
Version: 9
Hardware: x86_64
OS: Linux
low
low
Target Milestone: ---
Assignee: jmccann
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-12-07 11:02 UTC by basilicum
Modified: 2015-01-14 23:22 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2008-12-08 08:25:06 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description basilicum 2008-12-07 11:02:20 UTC
User-Agent:       Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.1.18) Gecko/20081112 Fedora/1.1.13-1.fc9 SeaMonkey/1.1.13

In Fedora 9 the gnome login window shows a list of a set of users. This looks pretty, (you can I think put a photo of the person), but is in fact a high security risk.

The login consists of two things: the username and the password. The password is to be secret at all times. However, the username is half of the secret, if a hacker has the username, he/she can try to break the password. 

There for this login window has a high security risk in it. At least you should be able to switch the showing of the list of users off. 

In fedora 8, you could switch of this list of users, why has it disappeared ? It looks funny a list of photographs, but in many situations it is a security risk.

Reproducible: Always

Steps to Reproduce:
1.
2.
3.

Comment 1 Tomas Hoger 2008-12-08 08:25:06 UTC

*** This bug has been marked as a duplicate of bug 449728 ***


Note You need to log in before you can comment on or make changes to this bug.