Uploaded image for project: 'Guacamole'
  1. Guacamole
  2. GUACAMOLE-1599

Storage of TOTP secrets unhashed

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Minor
    • Resolution: Invalid
    • 1.3.0
    • None
    • guacamole-auth-totp
    • None
    • Ubuntu 20.04

    Description

      Hi

      Successfully campaigned for the use of guacamole in the large public sector organisation I work at. A security-conscious colleague has noticed that apparently the TOTP codes for users are stored in the guacamole_user_attribute table in plain text - and presumably could be trivially copied to a TOTP utility and the codes generated.

      I pointed out that the user security part is salted and hashed, and you'd need both to log in, but the colleague is not appeased.

      Perhaps not a bug as such but possibly a spanner in the works of keeping the adoption of the software, which would be a big shame. Is there an official explanation (e.g. that it's simply not required as you'd need to get into the database first, the security is implicit there etc)? Or is it a future planned change?

      Thank you

      Attachments

        Activity

          People

            Unassigned Unassigned
            frankerooney Andy Franks
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: