Author [EN] [ZH] [ES] [PT] [IT] [DE] [FR] [NL] [TR] [SR] [AR] [RU] [EN] [ZH] [ES] [PT] [IT] [DE] [FR] [NL] [TR] [SR] [AR] [RU] [EN] [ZH] [ES] [PT] [IT] [DE] [FR] [NL] [TR] [SR] [AR] [RU] Topic: "Go Back" in lock screen  (Read 329 times)

0 Members and 1 Guest are viewing this topic.

Offline 麥可貓

  • Sr. Member
  • ****
  • Posts: 253
    • View Profile
"Go Back" in lock screen
« on: August 19, 2014, 09:27:21 AM »

In lock screen of qt_wallet, I just found that I can do the following things (now I am using 0.4.2 in ubuntu):
1. right click mouse, press "Go Back"
2. the wallet will really go back to the tab before screen locked, and there are a couple seconds before re-lock (this interval may vary depending on the final tab you are while pressing lock).
3. I can prepare a command in my clipboard, paste it, and hit ENTER. This step may require performing step 1-2 for multiple times.

I think basically the information of your account can be obtained using step 1-2 (account names in wallet, transaction histry, etc), and can do something more using step 3
« Last Edit: August 19, 2014, 10:42:59 AM by 麥可貓 »
PTS: PmRVDPymZqSAZEXauHZSewrUrE66af7epT
BTSX: michaelcat
Delegate Team: x1.sun  x2.sun

Offline bytemaster

Re: "Go Back" in lock screen
« Reply #1 on: August 19, 2014, 12:00:31 PM »
The underlying wallet is locked, your funds are safe. 


Sent from my iPhone using Tapatalk
For the latest updates checkout my blog: http://bytemaster.bitshares.org
Anything said on these forums does not constitute an intent to create a legal obligation or contract between myself and anyone else.   These are merely my opinions and I reserve the right to change them at any time.

Offline emski

  • Hero Member
  • *****
  • Posts: 1283
    • View Profile
    • http://lnkd.in/nPbhxG
Re: "Go Back" in lock screen
« Reply #2 on: August 19, 2014, 12:11:20 PM »
The underlying wallet is locked, your funds are safe. 


Sent from my iPhone using Tapatalk

What about transaction details, account names ?
If it is that easy to bypass passwords in the GUI it should be fixed... (not that a person with physical access to your PC cant obtain the data but why should it be that easy)...

Offline xeroc

  • Board Moderator
  • Hero Member
  • *****
  • Posts: 12060
  • ChainSquad GmbH
    • View Profile
    • ChainSquad GmbH
  • BTS: xeroc
  • GitHub: xeroc
Re: "Go Back" in lock screen
« Reply #3 on: August 19, 2014, 12:22:50 PM »
The underlying wallet is locked, your funds are safe.

What about transaction details, account names ?
If it is that easy to bypass passwords in the GUI it should be fixed... (not that a person with physical access to your PC cant obtain the data but why should it be that easy)...
If someone can get to your computer to perform described actions they can also get the raw data for your wallet .. in there account names and transaction details are plain text (for a good reason) only private keys are encrypted ..

when you press the lockout button the GUI performs a wallet_lock which deletes the private key from memory making it impossible to retreive the private key in unencrypted form ...

You are spreading FUD ..
Give BitShares a try! Use the http://testnet.bitshares.eu provided by http://bitshares.eu powered by ChainSquad GmbH

Offline emski

  • Hero Member
  • *****
  • Posts: 1283
    • View Profile
    • http://lnkd.in/nPbhxG
Re: "Go Back" in lock screen
« Reply #4 on: August 19, 2014, 12:35:08 PM »
The underlying wallet is locked, your funds are safe.

What about transaction details, account names ?
If it is that easy to bypass passwords in the GUI it should be fixed... (not that a person with physical access to your PC cant obtain the data but why should it be that easy)...
If someone can get to your computer to perform described actions they can also get the raw data for your wallet .. in there account names and transaction details are plain text (for a good reason) only private keys are encrypted ..

when you press the lockout button the GUI performs a wallet_lock which deletes the private key from memory making it impossible to retreive the private key in unencrypted form ...

You are spreading FUD ..
Scenario:
1 Unprivileged account using the wallet GUI through elevation.
2 Lockout
3 Expectation is that noone can see anything (locked GUI and unprivileged account).
The issue is that 3 is not true.

Offline bytemaster

Re: "Go Back" in lock screen
« Reply #5 on: August 19, 2014, 05:47:47 PM »
The underlying wallet is locked, your funds are safe.

What about transaction details, account names ?
If it is that easy to bypass passwords in the GUI it should be fixed... (not that a person with physical access to your PC cant obtain the data but why should it be that easy)...

It is a bug for sure, just not fatal.
If someone can get to your computer to perform described actions they can also get the raw data for your wallet .. in there account names and transaction details are plain text (for a good reason) only private keys are encrypted ..

when you press the lockout button the GUI performs a wallet_lock which deletes the private key from memory making it impossible to retreive the private key in unencrypted form ...

You are spreading FUD ..
Scenario:
1 Unprivileged account using the wallet GUI through elevation.
2 Lockout
3 Expectation is that noone can see anything (locked GUI and unprivileged account).
The issue is that 3 is not true.
For the latest updates checkout my blog: http://bytemaster.bitshares.org
Anything said on these forums does not constitute an intent to create a legal obligation or contract between myself and anyone else.   These are merely my opinions and I reserve the right to change them at any time.

 

Google+