Allow user to suppress individual fields when sending a report
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apport (Ubuntu) |
Triaged
|
Wishlist
|
Unassigned |
Bug Description
Binary package hint: apport
When apport detects a crash in an application that handles passwords there is a huge opportunity for an unwitting user to upload an attachment (i.e. a core file) with their password in it!
I'm not sure what the answer is to this problem. Initially I thought that applications that even come remotely close to handling passwords should be flagged and their bug reports be marked private when uploaded. That only limits possible password disclosure though.
Probably what is needed is some kind of password scrubbing tool that iterates over all of the attachments looking for a list of strings (i.e. passwords) and replace them with something like "***" (enough to fill the string). That would require that apport know a users password(s) in plain-text though. As bad as that is, sending passwords to an open and public bug reporting system is even worse.
Thots?
Changed in apport: | |
status: | Unconfirmed → Needs Info |
Changed in apport: | |
importance: | Low → Medium |
assignee: | nobody → pitti |
Changed in apport (Ubuntu): | |
assignee: | Martin Pitt (pitti) → nobody |
Changed in apport (Ubuntu): | |
importance: | Medium → Wishlist |
information type: | Public → Public Security |
Have you an example of this ? I think it doesn't includes that type of information...