Passphrase not verified for encrypted homes

Bug #495339 reported by WubiNeophyte
This bug report is a duplicate of:  Bug #359997: Improve record-your-passphrase dialog. Edit Remove
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ecryptfs-utils (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Binary package hint: ecryptfs-utils

I recently installed Karmic Koala, and opted for an encrypted home. I was horrified at the interface for doing this, however. My biggest concern was that the passphrase I was expected to create was never asked to be confirmed. I thought this was routine practice by now.

The obvious concern is that something as small as a typo is enough to permanently cause data loss with this configuration. While this issue seems to have been raised in bug 359997, the bug is older than Karmic, and marked fixed. I asked whether the issue had been corrected, but didn't get a response.

Solution: new bug

WubiNeophyte (wubibugs)
description: updated
Revision history for this message
Dave Walker (dogatemycomputer) wrote :

I would be happy to confirm this bug but I would like to get some additional information so I am sure what the problem is. I personally do not use an encrypted home but I am happy to setup a test machine, reproduce the problem so I can confirm the bug. This is necessary before a developer has an opportunity to examine the bug.

At a minimum, we need:
1. the specific steps or actions you took that caused you to encounter the problem,
2. the behavior you expected, and
3. the behavior you actually encountered (in as much detail as possible).

If you feel the information you have already provided should be enough for a developer to identify and resolve the problem then please update this bug report. A more experienced triager may come along and confirm the bug without my involvement.

Thank you for taking the time to report this bug and helping to make Ubuntu better!

Revision history for this message
WubiNeophyte (wubibugs) wrote :

Dave,

Not sure I'll be able to clarify much for you. Now that the install is complete, I have no plans to retry until it's necessary. Am reporting the bug because I'm hoping to avoid potential issues in the future.

I don't think I did anything fancy. I just installed Karmic from the CD installer. I found an option in one of the steps that allowed for encrypted homes, so I enabled the option. I don't remember after that point when I was prompted for the passphrase. It may have been during the install itself, but more likely, as I'm gathering from other sources, it was launched post-install by a notification window. The prompts weren't from a full-fledged GUI like GTK, but I don't remember if it was a shell script or some kind of ad-hoc widget.

When I was prompted for the passphrase, I wondered if it would ask me to confirm. Since I wasn't sure, I was careful entering the passphrase, but after hitting enter to accept the passphrase, I wasn't prompted to verify. I expected a second prompt to verify the passphrase entry (like passwords are verified).

I feel like I'm repeating myself, so if there's something specific you're looking for, please let me know, and I'll see if I remember. If you have a machine that you could set up to test this, then perhaps you could actually reproduce this, as I don't think this is an intermittent problem. Based on bug 359997, I would venture to say that the issue should be reproducible on a test install image by running the ecryptfs-unwrap-passphrase script.

Changed in ecryptfs-utils (Ubuntu):
status: New → Invalid
Revision history for this message
Mike (bild85) wrote :

is this a dup of bug 359997?

Revision history for this message
WubiNeophyte (wubibugs) wrote :

As I stated in the question version of this bug, this issue is not resolved.

The dialogue presented to the user is in no way user-friendly, and provokes the response that is seen here. An implied response of RTFM is not acceptable, as Ubuntu is intended for Human Beings.

This bug should address the actual failure here, which appears to be one of communication, indicating that the dialogue is inadequate.

Revision history for this message
WubiNeophyte (wubibugs) wrote :

itismike: it is not a dupe. I intentionally filed this separately, as I can't speak to the other issues in bug 359997. One issue, one bug. This certainly could be solved without solving bug 359997.

Revision history for this message
WubiNeophyte (wubibugs) wrote :

No reason given as to why this was marked invalid. Reinstating.

Changed in ecryptfs-utils (Ubuntu):
status: Invalid → New
Revision history for this message
Mike (bild85) wrote :

Actually I think it is invalid. The prompt was incredibly confusing, and wasn't actually _asking_ for a passphrase... it was about to _give_ you an automatically-generated passphrase, so you can write it down if you like. See PhysicsDan's clarification here:
https://bugs.launchpad.net/ecryptfs/+bug/359997/comments/15

Revision history for this message
WubiNeophyte (wubibugs) wrote :

itismike,

Ok. That sort of makes sense now. Unfortunately, I still have two issues with the dialog that is presented, as of the Lucid Beta:

1) The dialog is still pretty confusing, with lots of poor word choices, and poor explanations for end users.
2) The button to show the "unwrapped" password didn't work for me in the Lucid Beta (fresh install); it did nothing.

What do you recommend?

Revision history for this message
Mike (bild85) wrote :

I think both issues will be resolved with bug 359997. You may want to add your second comment to that bug and ask if it's appropriate to open another bug for that. This one I'd mark as Invalid.
-MIke

Mike (bild85)
Changed in ecryptfs-utils (Ubuntu):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.