[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-13 Thread Launchpad Bug Tracker
This bug was fixed in the package pithos - 0.3.8-1 --- pithos (0.3.8-1) unstable; urgency=high * New upstream bugfix release. * SECURITY UPDATE: Pandora password leak to local users. (LP: #733307) - pithos/PreferencesPithosDialog.py: correct mode on pithos.ini on next ru

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-13 Thread Luke Faraone
** Changed in: pithos (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/733307 Title: password stored in plaintext in $HOME/.config/pithos.ini -- u

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-12 Thread Reed Loden
Why even offer the 'unsafe_permissions' option at all? Do you actually know of a specific case where a user would need different permissions on the file? Seems like it would be unwise to add configuration options "just because". -- You received this bug notification because you are a member of Ub

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-12 Thread Kevin Mehall
** Changed in: pithos Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/733307 Title: password stored in plaintext in $HOME/.config/pithos.ini -- ubuntu-bu

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-12 Thread Kevin Mehall
** Changed in: pithos Status: Triaged => Fix Committed ** Changed in: pithos Assignee: (unassigned) => Luke Faraone (lfaraone) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/733307 Title:

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-11 Thread Luke Faraone
** Branch linked: lp:~lfaraone/pithos/password-permissions-fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/733307 Title: password stored in plaintext in $HOME/.config/pithos.ini -- ubuntu-bugs m

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-08 Thread Reed Loden
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2011-1500 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/733307 Title: password stored in plaintext in $HOME/.config/pithos.ini -- u

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-08 Thread Luke Faraone
Not as far as we're aware; the main login method used by the Pandora web client sends the password symmetrically encrypted. We'll look into possibly logging in via SSL and transferring from an HTTP cookie to a LSO, but the protocol's use of blowfish means that the authentication token (be it passw

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-08 Thread Reed Loden
Is it not possible to send the login information over SSL? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/733307 Title: password stored in plaintext in $HOME/.config/pithos.ini -- ubuntu-bugs maili

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-08 Thread Luke Faraone
** Changed in: pithos (Ubuntu) Status: New => In Progress ** Changed in: pithos (Ubuntu) Assignee: (unassigned) => Luke Faraone (lfaraone) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/733

[Bug 733307] Re: password stored in plaintext in $HOME/.config/pithos.ini

2011-04-08 Thread Luke Faraone
** Visibility changed to: Public ** Description changed: - should be stored in md5sum. + The configuration file which stores authentication for Pandora is world + readable. This allows other local users to read a user's authentication + credentials. -- You received this bug notification because