| Prev |   2     3   4   5     6   14 | Next | Last
maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Maemo 5 / Fremantle (https://talk.maemo.org/forumdisplay.php?f=40)
-   -   IM, Email Passwords Are Stored as Plain Text (https://talk.maemo.org/showthread.php?t=41164)

Venomrush 2010-01-18 12:02

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
Quote:

Originally Posted by Andre Klapper (Post 479689)
That's fixed in 2.2009.51-1, see https://bugs.maemo.org/show_bug.cgi?id=5419 . Please always mention which version you are running.

That's for Wifi not browser.
Not sure if there's one filled for browser as well.

mece 2010-01-18 12:15

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
Why is everyone acting surprised? Most Im clients are like this.
I don't mind this, but it would be nice with a keyring type option.

You could read this for perspective:
http://developer.pidgin.im/wiki/PlainTextPasswords

Venomrush 2010-01-18 12:21

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
Quote:

Originally Posted by mece (Post 479721)
Why is everyone acting surprised? Most Im clients are like this.
I don't mind this, but it would be nice with a keyring type option.

You could read this for perspective:
http://developer.pidgin.im/wiki/PlainTextPasswords

Last Modified by petr.bug, 16 months ago

You should not apply what being said in this article to today's world where security takes priority, where there's a massive growth in the smart mobile market and Web 2.0 usage such as blogging Twitter Facebook etc.

Users are now becoming more concern with their privacy and the risks of identity theft.

slender 2010-01-18 12:22

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
mece, its true and at least i'n not surprised but off course its bit worrying when you have for example google services password exposed. You can also load money to skypeout. These are not anymore "just" traditional IM clients.

MartinNZ 2010-01-18 12:27

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
Quote:

Originally Posted by Andre Klapper (Post 479689)
That's fixed in 2.2009.51-1, see https://bugs.maemo.org/show_bug.cgi?id=5419 . Please always mention which version you are running.

i am running the most current .51. it is still caching my passwords for autocomplete.

MartinNZ 2010-01-18 12:30

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
Quote:

Originally Posted by Andre Klapper (Post 479693)
Of course it will as your dictionary file does not get overwritten. I don't think you want to start teaching the N900 from scratch?
You have to remove that string from the dictionary first...

thanks andre.... it aint too straightforward to purge the dict tho. does nokia expect all the users to do this?

PhilE 2010-01-18 12:31

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
Yup definitely a case of moleHill != Mountain

Regardless of whether you're talking about a mobile phone, PDA, laptop, desktop or even a server in a data centre, once the miscreant has physical access, there's little you can do to stop your data being compromised, unless you've gone as far as implementing things like whole-disk encryption or similar.

There are other bugs that I'd (personally) far rather the Maemo team spent their time on.

scudderfish 2010-01-18 12:33

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
If you don't have physical control of the device when it is in an unlocked state, all bets are off for data integrity. I'd be more worried about someone racking up a huge phone bill with my phone than them getting an IM password.

slux 2010-01-18 12:37

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
Quote:

Originally Posted by Venomrush (Post 479729)
Last Modified by petr.bug, 16 months ago

You should not apply what being said in this article to today's world where security takes priority, where there's a massive growth in the smart mobile market and Web 2.0 usage such as blogging Twitter Facebook etc.

Users are now becoming more concern with their privacy and the risks of identity theft.

Nothing discussed in that article has changed. A false sense of security achieved by obscuring the passwords that are still trivially recoverable does not become any better in a world where "security takes priority".

slender 2010-01-18 12:42

Re: Warning - Exploit found, keep N900 to yourself until it's fixed!
 
So its all or nothing? Black or white?

There is no different levels of security?


| Prev |   2     3   4   5     6   14 | Next | Last
All times are GMT. The time now is 21:37.

vBulletin® Version 3.8.8