Comment 41 for bug 41134

Revision history for this message
Mika Fischer (zoop) wrote :

I also recently found out that NM stores the password for the WLAN at my university in clear text in the gconf database.

In my optinion this is a huge security issue! At my university students get ONE password for their shell acounts, email, logins to administrative websites, etc pp. And of course for access to the campus WLAN. And this one password is stored in clear-text on my computer. So I only need to leave my laptop unattended for a minute and this would be enough for an attacker (who probably knows what can be done with the password because he's a student too) to steal my password! Needless to say, a lot of bad stuff can happen after that...

I really cannot believe that this bug has been open for almost TWO years now with priority medium...

For me, storing the password in clear-text is vastly worse than not storing it at all!

I'll try to have a look at the network-manager code to see if I can do anyhting, but don't hold your breath...

If anyone can get the attention of the security people to this, that would be great!