[Pidgin] #5802: Change password feature works incorrect for ICQ (and maybe other) account. It is not test whether the original password is correct.

Pidgin trac at pidgin.im
Thu May 15 19:46:40 EDT 2008


#5802: Change password feature works incorrect for ICQ (and maybe other) account.
It is not test whether the original password is correct.
-----------------------+----------------------------------------------------
  Reporter:  vkhandus  |       Owner:  MarkDoliner
      Type:  defect    |      Status:  new        
  Priority:  minor     |   Milestone:             
 Component:  ICQ       |     Version:  2.4.1      
Resolution:            |    Keywords:  password   
   Pending:  0         |  
-----------------------+----------------------------------------------------
Comment (by MarkDoliner):

 I think ICQ doesn't need the original password when you change your
 password.  So there are two things we could do to fix this, which one do
 people prefer?

 1. Remove the "Original password" field from the dialog when it isn't
 needed.

 2. Always verify that the "Original password" field is correct, even when
 this isn't required by the protocol.  This might be a tad bit more secure,
 in the case where you sign into Pidgin, wander away from your computer,
 and a malicious user comes along and changes your password unbeknowest to
 you.

-- 
Ticket URL: <http://developer.pidgin.im/ticket/5802#comment:1>
Pidgin <http://pidgin.im>
Pidgin


More information about the Tracker mailing list