Bug#741678:

2014-08-24 Thread Francois L
I didn't reopen the bug, I just unarchived it to be able to add a message. But maybe it should be reopened until it is fixed in both debian-old-3.0 and debian? Jessie won't be released until May-June 2015 maybe. Closing the bug makes it appear under "Resolved bugs", which is unlikely to grab any

Bug#741678:

2014-08-24 Thread Daniel Baumann
close 741678 4.0~alpha33-1 thanks On 08/25/2014 01:59 AM, Francois L wrote: > Surely the fix should have made it to Debian Live 7.6 by now? the bug was fixed in above version of live-config. wheezy uses live-config 3.x. the bug was versioned closed (and now versioned closed again), that means it

Bug#741678:

2014-08-24 Thread Francois L
I see that the bug is marked as fixed, but it's still there in the latest Debian. Here's the timeline: 2014-04-26 Debian 7.5 released 2014-04-27 Bug marked as fixed 2014-05-05 Debian Live 7.5 released 2014-07-12 Debian 7.6 released 2014-07-23 Debian Live 7.6 released Surely the fix should have m

Bug#741678: It is possible to use live user account to log in via SSH

2014-03-15 Thread Evgeny Kapun
It is never mentioned in debian-live documentation that it is unsafe to connect to untrusted networks from a live system. If this is intended, it should be said clearly. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact list

Bug#741678: It is possible to use live user account to log in via SSH

2014-03-15 Thread Evgeny Kapun
I think that it is wrong if anyone on the same network can log into a live system and get full access to it. If a user connects, say, to a Wi-Fi network to download something, he doesn't expect his computer to become open to everyone. Currently, it is necessary to change the password before conn

Bug#741678: It is possible to use live user account to log in via SSH

2014-03-15 Thread Daniel Baumann
severity 741678 normal tag 741678 - security tag 741678 moreinfo thanks On 03/15/2014 03:24 PM, Evgeny Kapun wrote: > By default, live-config creates a user with known name (user) and password > (live). In live images with included openssh-server, this means that anyone > can log into a live sys

Bug#741678: It is possible to use live user account to log in via SSH

2014-03-15 Thread Evgeny Kapun
Package: live-config Version: 4.0~alpha31-1 Severity: important Tags: security By default, live-config creates a user with known name (user) and password (live). In live images with included openssh-server, this means that anyone can log into a live system immediately once it connects to a netwo