security issues in gtkentry



i'm not sure if this has been brought up before, but when a gtkentry is
not visible (text appears as '*'), it's still selectable. unfortunately,
this defeats the purpose of blocking the view of entered text.

as an example, imagine someday you're using GNUzilla or whatever, buying
some kicking 20gig optical hard drive over the web. your annoying little
nephew, who prides himself on being an elite hax0r type is sitting at
another computer in the room. you login to the site with a non-visible
gtkentry to hide your password, flag the merchanise you want, and finish
the transaction. excited with your new purchase, you leave the room to get
a drink. your nephew notices your departure, hits "Back" on the browser a
few times, selects the hidden password and pastes in an xterm. just
imagine if he tells his kewl friends and they start ordering big bad
computer equipment to your account.

i think it would be best to just not allow non-visible text to be
pastable. the right-click gray selection could be used for the first
button. sorry if i can't provide a patch, after looking at gtkentry.c i
don't think i'm familiar enough to do The Right Thing.
 _        _  __     __             _ _                                  _
|        / |/ /_ __/ /_____         |       Nuke Skyjumper               |
|       /    / // /  '_/ -_)        |         "Master of the Farce"      |
|_     /_/|_/\_,_/_/\_\\__/        _|_           nuke@bayside.net       _|



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]