PDA

View Full Version : bad security flaw


brodie
04-13-2002, 10:53 AM
now i know this seems to be obvious, but unlocking your keychain not only gives applications access to passwords, it also gives anyone who has access to your unlocked keychain visible access to all your passwords.
i don't mind the fact that passwords are given to apps etc and appear as bullets, but i find it a bit of a security flaw that i have a complete list of all my passwords if i unlock the keychain. surely a pwd prompt to view the password should be given in the keychain app, whilst unlocking the keychain only gives apps "bullet" access.
does that make sense?:confused:

didde
04-13-2002, 11:06 AM
yeah, I understand what you mean but still, wouldn't it be a pain if you had to "unlock" the chain everytime you wanted to have look at a password? I use the chain to store passwords I frequently use on the web and so on. When I'm not in the keychain access.app I keep it locked..

taikahn
04-13-2002, 11:10 AM
Actaully the keychain access application does ask for the keychain password everytime you want to view a password. It asks in the familiar format of: Deny, Allow Once, or Always Allow. If you picked Always Allow you will NEVER be promted again. If you pick DENY you will be prompted EVERY time.

Tai Kahn

brodie
04-13-2002, 11:15 AM
it doesn't ask for a password, it merely asks for access. the deal is, once your keychain is unlocked, you can view any of your passwords.
i would like apps to have access to my passwords, but i want a pwd prompt if i want to view that password.

taikahn
04-13-2002, 11:36 AM
****, your right. That is a bad way to do that.