[Pidgin] #3810: Annoyance / Possible Security Issue with Multiple Accounts

Pidgin trac at pidgin.im
Thu Nov 1 10:05:30 EDT 2007


#3810: Annoyance / Possible Security Issue with Multiple Accounts
--------------------------+-------------------------------------------------
 Reporter:  ljbuesch      |       Type:  defect
   Status:  new           |   Priority:  minor 
Component:  pidgin (gtk)  |    Version:  2.2.1 
 Keywords:                |    Pending:  0     
--------------------------+-------------------------------------------------
 When logging into Pidgin with multiple accounts, you are given several
 password dialogs.  If you happen to enter your password into one of them
 being an AIM account that is already logged into another computer, you get
 an AIM conversation with it telling you that you can remote-logoff your
 other accounts.  The problem with this, is that it becomes the new active
 window, and if you were typing a password in another one of your login
 dialog's, it will start to show up in the AIM conversation box.  This
 (possibly) could also happen if you receive a new IM message from someone
 before you are done entering all of your passwords and could possibly send
 parts if not all of your password to them if you are not paying attention.
 Or if someone is peering over your shoulder, they would see parts of your
 password.

 Possible course of action:

 Make sure that new windows that pop up are not the active window when a
 password dialog is open.

 OS:
 Ubuntu 7.10

-- 
Ticket URL: <http://developer.pidgin.im/ticket/3810>
Pidgin <http://pidgin.im>
Pidgin


More information about the Tracker mailing list