! Please note that this is a snapshot of our old Bugzilla server, which is read only since May 29, 2020. Please go to gitlab.xfce.org for our new server !
Passwords stored in clear text in ~/.config/xfce4/panel/mailwatch
Status:
RESOLVED: DUPLICATE
Product:
Xfce4-mailwatch-plugin
Component:
General

Comments

Description chocolate.camera 2009-12-09 06:07:47 CET
Overview:

Passwords for e-mail accounts are stored in clear text in the /home/user_name/.config/xfce4/panel/mailwatch which is a security risk

Steps to Reproduce:

1) Configure one or more e-mail accounts, logout and relogin (last two steps may not be necessary)

2) Navigate to ~/.config/xfce4/panel/, and see the contents of mailwatch-[string_of_numbers].rc

Actual Results:

Passwords for every mail account are displayed without any sort of encryption

Expected Results:

Passwords should be masked with some sort of encryption or not be there at all. I do not know if mailwatch can expect to have the OS provide a specific keychain-like central encrypted password storage service.

Version:
Xfce 4 Mailwatch Plugin 1.1.0 on Xfce 4.6.1
Comment 1 Brian J. Tarricone (not reading bugmail) 2009-12-09 06:36:33 CET

*** This bug has been marked as a duplicate of bug 3516 ***

Bug #6062

Reported by:
chocolate.camera
Reported on: 2009-12-09
Last modified on: 2010-11-09

People

Assignee:
Brian J. Tarricone (not reading bugmail)
CC List:
1 user

Version

Version:
1.1.0 or older

Attachments

Additional information