Re: spice-client: "-w password" (on the command line) is a security risk

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sun, Apr 07, 2013 at 09:05:34PM -0500, Rob Browning wrote:
> (If possible, please preserve the 704229-forwarded address in any replies.)
> 
> I reported the following bug to the Debian bug tracker, but realized it
> should probably just be forwarded upstream.
> 
> Rob Browning <rlb@xxxxxxxxxxxxxxxx> writes:
> 
> > Package: spice-client
> > Version: 0.11.0-1
> >
> > I think the spice client should probably support some other way of
> > specifying the password since putting it on the command line makes it
> > visible to any other users on the system.
> >
> > A reasonable alternative might be "--password-file foo".
> 
> (cf. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=704229)

The recommended client these days is remote-viewer which does not allow
passing the password on the command line, so this is less of an issue

Christophe

Attachment: pgpeITfCqK87q.pgp
Description: PGP signature

_______________________________________________
Spice-devel mailing list
Spice-devel@xxxxxxxxxxxxxxxxxxxxx
http://lists.freedesktop.org/mailman/listinfo/spice-devel

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]     [Monitors]