FLAM® Issue Tracker

View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0000488CLE/P2. CLPpublic2014-06-26 08:322014-06-27 13:31
ReporterFalk Reichbott 
Assigned ToFalk Reichbott 
PriorityhighSeverityfeatureReproducibilityhave not tried
StatusresolvedResolutionfixed 
PlatformGeneralOSGeneralOS VersionGeneral
Product Version1.1 
Target Version1.2Fixed in Version1.1 
Summary0000488: Prevent logging and tracing of passwords
DescriptionThe type string is currently used to handle passwords and passphrases, but normal strings are traced as lexems, part of the parsed parameter list aso. For security reasons it would be helpful to have a flag which prevents logging in clear form of this parameter.

Additional it would be helpful to have a own type for passphrases, where the scanner at once calculate a one way hash value and the type is a fix 32 byte array containing the hashed string value, which can be used for example as 256 bit key.
TagsNo tags attached.
Attached Files

- Relationships

-  Notes
There are no notes attached to this issue.

- Issue History
Date Modified Username Field Change
2014-06-26 08:32 Falk Reichbott New Issue
2014-06-26 08:32 Falk Reichbott Status new => assigned
2014-06-26 08:32 Falk Reichbott Assigned To => Falk Reichbott
2014-06-27 13:31 Falk Reichbott Status assigned => resolved
2014-06-27 13:31 Falk Reichbott Fixed in Version => 1.1
2014-06-27 13:31 Falk Reichbott Resolution open => fixed


Copyright © 2000 - 2024 MantisBT Team
Powered by Mantis Bugtracker