MDM store my password to environment variable ?
lbngoc opened this issue · comments
* Cinnamon version (cinnamon --version) 3.2.7
* Distribution - (Mint 17.2, Arch, Fedora 25, etc...) Mint 18.1
* 64 bit
* kernel 4.4.0-66-generic
Issue
After computer start and logged in, my current password was stored as plain text (!!!) to environment variable ($LANG & $MDM_LANG)
Steps to reproduce
- Start computer
- Login to current user
Expected behaviour
- $LANG and $MDM_LANG is same with
/etc/default/locale
- The system SHOULD NOT store password as plain text in any case.
Other information
- When on MDM login screen, if I select language and login, $LANG and $MDM_LANG is set same with my selection. But it is only affect with this session.
Hi, does anyone review and support this issue ?
I strongly believe that I can confirm this issue, because it could explain the behaviour which I discovered with the login screen.
When I move the mouse over the empty locale selection of the login screen, a "mouse over" text opens which shows the clear password selected user; see attached screen shots. Once a language is selected, everything is fine.
Adding a new user (who wasn't logged in) does not show the behaviour.
I have reported this to the linux mint bug list
https://bugs.launchpad.net/linuxmint/+bug/1720278
Distributor ID: LinuxMint
Description: Linux Mint 18.1 Serena
Release: 18.1
Codename: serena
Cinnamon
Linux 4.8.0-58-generic #63~16.04.1-Ubuntu SMP Mon Jun 26 18:08:51 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux