← Back to team overview

ecryptfs team mailing list archive

Re: [Bug 370627] Re: Inadvertent opening of encrypted dir

 

On Fri, Jul 24, 2009 at 5:06 PM, markb<mark.blakeney@xxxxxxxxxxxxxxxxxx> wrote:
> Dustin, I am on the current release of ubuntu (i.e. jaunty) and am
> running the latest ecryptfs-utils package I can find, i.e.
> 74-0ubuntu1~ppa1 from your ppa. It still exhibits this bug daily. Is
> there any chance you can produce an updated package for jaunty?

The Karmic ecryptfs-utils package is not backwards compatible with
Jaunty.  I'd need to do some non-trivial build work to get it going.
Sorry.

:-Dustin

-- 
Inadvertent opening of encrypted dir
https://bugs.launchpad.net/bugs/370627
You received this bug notification because you are a member of eCryptfs,
which is a direct subscriber.

Status in eCryptfs - Enterprise Cryptographic Filesystem: Fix Released

Bug description:
I've found what I think is quite a significant bug in ecryptfs. I am a user who has auto-login enabled so it means that ecryptfs correctly (as designed) does not automatically mount ~/.Private/. I've discovered that any time you use "sudo" that your password get installed in the kernel keyring and your ~/.Private dir becomes automatically available to be mounted merely by (anybody) clicking on the standard "Access your Private data" link. No password/passphrase is then required to be explicitly entered to open your private dir. The same problem applies even if you don't use auto-login - you may think you have closed off private access with ecryptfs-umount-private but a simple sudo somewhere else makes your private directory available again without entering a password.

It is un-reasonable and dangerous that a typical naive user should have to be aware that he has exposed his private dir just because he did an sudo somewhere completely unrelated. There should be no correlation between sudo and this ecryptfs functionality.

I'm using ecryptfs-utils version 73-0ubuntu6 on jaunty.



References