After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 745348 - fingerprint reader doesn't need password
fingerprint reader doesn't need password
Status: RESOLVED NOTGNOME
Product: gnome-control-center
Classification: Core
Component: User Accounts
unspecified
Other Linux
: Normal major
: ---
Assigned To: Ondrej Holy
Control-Center Maintainers
Depends on:
Blocks:
 
 
Reported: 2015-03-01 01:52 UTC by tim
Modified: 2015-03-03 11:48 UTC
See Also:
GNOME target: ---
GNOME version: ---


Attachments
allow changing fingerprints only when authorized (2.10 KB, patch)
2015-03-03 07:53 UTC, Ondrej Holy
needs-work Details | Review

Description tim 2015-03-01 01:52:22 UTC
No password is necassary to config the fingerprint reader. I think this is a security issue:

1. Persons with physical access can scan their own fingerprint. So they can do everything that is allowed for this specific user.

2. If the user owns system privileges (sudo) the person has access to the hole system.
Comment 1 Ondrej Holy 2015-03-03 07:53:52 UTC
Created attachment 298372 [details] [review]
allow changing fingerprints only when authorized

Thanks for your bug report. You are right, that it could be security issue. Attaching patch to fix it...
Comment 2 Bastien Nocera 2015-03-03 10:54:33 UTC
Review of attachment 298372 [details] [review]:

That doesn't work. If I'm not an admin, how do I change my fingerprint? The panel gets unlocked with the admin password, and this only papers over the issue, as you can still run fprintd-enroll to enroll a new one.
Comment 3 Ondrej Holy 2015-03-03 11:48:56 UTC
Thanks for review, you are right, I didn't realize that, so this is fprintd bug, not gnome. So we will require password once it will be required by fprintd...

I've filed it to fprintd...
https://bugs.freedesktop.org/show_bug.cgi?id=89407