~desa

Recent activity

Re: Plaintext passwords potentially being exposed through format macro 5 months ago

From Luca De Santis to ~kennylevinsen/greetd-devel

I have the same issue, I think the problem is with the pam
fprintd-grosshack and greetedd module because there is the same
problem with other greeters that use fprintd-grosshack and greetedd.
In my greeter (tuigreet) logs I found these events:
1. tuigreet sends "CreateSesssion"
2. tuigreet receives from greeted an "AuthMessage" of type "Secret"
3. At this moment the screen is waiting for password or fingerprint
(fingerprint reader is up and running)
4. Now if you use fingerprint for authentication, the fingerprint
reader is disabled (I think because the fingerprint reading was
successful) but nothing happens, no message sent by tuigreet or
greeted.
5. If after using the fingerprint you type a password, even if it is
incorrect, tuigreet sends a "PostAuthMessageResponse" with the