desktop-packages team mailing list archive
-
desktop-packages team
-
Mailing list archive
-
Message #134153
[Bug 1474182] Re: Mystery keyring password prompts pop up for no reason
** Changed in: gnome-session (Ubuntu)
Importance: Undecided => High
--
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to gnome-session in Ubuntu.
https://bugs.launchpad.net/bugs/1474182
Title:
Mystery keyring password prompts pop up for no reason
Status in gnome-session package in Ubuntu:
Confirmed
Bug description:
A prompt box periodically pops up for no apparent reason asking me for
my default keyring password. If I click Cancel, it re-appears again
after a few minutes. There is absolutely no information about what
program is asking or why. Is this a phishing scam?!?
I'm marking this as "security vulnerability" because the "mystery"
prompt is asking for extremely sensitive information which users
should not give out without knowing what program will use it.
* My homedir is not encrypted
* I do use automatic login, but it succeeded and everything works, including network.
* My system has slept/resumed a few times (don't know if that's relevant)
* I use a wired Ethernet connection, not WiFi (so no password is needed for network access).
* I am not running any commands that I know of which use encryption or require access to my private keys.
Since I am not doing anything which actually requires my private key,
something is asking to unlock the keyring wrongly;
Or else a background process (or trojan) is trying to communicate with
somebody behind my back, using my private keys.
This seems to be new (REGRESSION) as of 15.04, it did not occur before
upgrading.
The programs I *am* running are:
* Firefox
* Thunderbird (I typed in it's Master Password previously, and it is working fine)
* Terminals
* A Java based web app (Interactive Brokers Trader Workstation)
/var/log/auth.log contains the following:
<username>: Executing command [USER=root] [TTY=unknown] [CWD=/home/<username>] [COMMAND=/usr/lib/update-notifier/package-system-locked]
bus acquired: org.gnome.keyring.SystemPrompter
Gcr: registering prompter
bus acquired: org.gnome.keyring.PrivatePrompter
Gcr: received BeginPrompting call from callback /org/gnome/keyring/Prompt/p22@:1.259
Gcr: preparing a prompt for callback /org/gnome/keyring/Prompt/p22@:1.259
Gcr: creating new GcrPromptDialog prompt
Gcr: automatically selecting secret exchange protocol
Gcr: generating public key
Gcr: beginning the secret exchange: [sx-aes-1]\npublic=RnT9opj6kZDvJpr8QyIBH4DE/xn3wid1Di7mdEuIgT/GCBA1mLB3VdsldoT6WMdJeD15xlSIvvmAiLLR59dffthvV+cifN3K1WoJhFdBDSiBLmkI4wfGXEnQTmJn7iZfyGWsIVqL5cSgG3AEMGKgY4ORzBARp8TLqjnfnoJB3YSh/gNFVs5OT5pCATNeaDN1mx9LzOCuCSwVDXIIY6uV8sjhBpBvQQCNNEV960L2pZYvGsBYMKeriKxvZAJfiO04\n
Gcr: calling the PromptReady method on /org/gnome/keyring/Prompt/p22@:1.259
acquired name: org.gnome.keyring.SystemPrompter
acquired name: org.gnome.keyring.PrivatePrompter
Gcr: returned from the PromptReady method on /org/gnome/keyring/Prompt/p22@:1.259
Gcr: received PerformPrompt call from callback /org/gnome/keyring/Prompt/p22@:1.259
Gcr: receiving secret exchange: [sx-aes-1]\npublic=RL9s/tyPJRw80JDQNBGC+0uQxXfk1uAvJH9XoAULcI4ys/b/Rfz9QNvujXVlhp02Yot7S7K6l5KLBc3i6Ry9SPECjeDm6Y5E4Ry43OmOKjBf7JBUcUvrzfUvwJ87YZ0fYCW8j9nDgrBxt1utCOUDJDHVVANdIK8CMIEXnffiKYjsPq8yjueenqdnM+G8VUoBke8U1Bmc0IHs8elTBBWnoeLQdpnLcpn7k245vO5V4w8Gl3ZZtYrw7t6xxZstRAXR\n
Gcr: deriving shared transport key
Gcr: deriving transport key
Gcr: starting password prompt for callback /org/gnome/keyring/Prompt/p22@:1.259
Gtk: GtkDialog mapped without a transient parent. This is discouraged.
Gcr: completed password prompt for callback :1.259@/org/gnome/keyring/Prompt/p22
Gcr: sending the secret exchange: [sx-aes-1]\npublic=RnT9opj6kZDvJpr8QyIBH4DE/xn3wid1Di7mdEuIgT/GCBA1mLB3VdsldoT6WMdJeD15xlSIvvmAiLLR59dffthvV+cifN3K1WoJhFdBDSiBLmkI4wfGXEnQTmJn7iZfyGWsIVqL5cSgG3AEMGKgY4ORzBARp8TLqjnfnoJB3YSh/gNFVs5OT5pCATNeaDN1mx9LzOCuCSwVDXIIY6uV8sjhBpBvQQCNNEV960L2pZYvGsBYMKeriKxvZAJfiO04\n
Gcr: calling the PromptReady method on /org/gnome/keyring/Prompt/p22@:1.259
Gcr: returned from the PromptReady method on /org/gnome/keyring/Prompt/p22@:1.259
Gcr: received PerformPrompt call from callback /org/gnome/keyring/Prompt/p22@:1.259
Gcr: stopping prompting for operation /org/gnome/keyring/Prompt/p22@:1.259
Gcr: closing the prompt
ProblemType: Bug
DistroRelease: Ubuntu 15.04
Package: gnome-session-bin 3.14.0-2ubuntu5
ProcVersionSignature: Ubuntu 3.19.0-23.24-generic 3.19.8-ckt2
Uname: Linux 3.19.0-23-generic x86_64
NonfreeKernelModules: nvidia
ApportVersion: 2.17.2-0ubuntu1.1
Architecture: amd64
CurrentDesktop: Unity
Date: Mon Jul 13 18:56:02 2015
InstallationDate: Installed on 2013-08-06 (707 days ago)
InstallationMedia: Ubuntu 13.04 "Raring Ringtail" - Release amd64 (20130424)
SourcePackage: gnome-session
UpgradeStatus: No upgrade log present (probably fresh install)
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/gnome-session/+bug/1474182/+subscriptions