linuxmint / mdm

The MDM Display Manager

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

MDM store my password to environment variable ?

lbngoc opened this issue · comments

 * Cinnamon version (cinnamon --version) 3.2.7
 * Distribution - (Mint 17.2, Arch, Fedora 25, etc...)  Mint 18.1
 * 64 bit 
 * kernel 4.4.0-66-generic

Issue
After computer start and logged in, my current password was stored as plain text (!!!) to environment variable ($LANG & $MDM_LANG)

Steps to reproduce

  • Start computer
  • Login to current user

Expected behaviour

  • $LANG and $MDM_LANG is same with /etc/default/locale
  • The system SHOULD NOT store password as plain text in any case.

Other information

  • When on MDM login screen, if I select language and login, $LANG and $MDM_LANG is set same with my selection. But it is only affect with this session.

Hi, does anyone review and support this issue ?

I strongly believe that I can confirm this issue, because it could explain the behaviour which I discovered with the login screen.

When I move the mouse over the empty locale selection of the login screen, a "mouse over" text opens which shows the clear password selected user; see attached screen shots. Once a language is selected, everything is fine.

Adding a new user (who wasn't logged in) does not show the behaviour.

I have reported this to the linux mint bug list

https://bugs.launchpad.net/linuxmint/+bug/1720278

Distributor ID: LinuxMint
Description: Linux Mint 18.1 Serena
Release: 18.1
Codename: serena
Cinnamon
Linux 4.8.0-58-generic #63~16.04.1-Ubuntu SMP Mon Jun 26 18:08:51 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux

This indeed looks to be the same issue as #220. As that has more information I'm closing this one. Please add any further information to the other issue.