-
dEBRUYNE
-
selsta
good point
-
xmr-pr
selsta opened pull request #2959: SettingsLayout: ask password for password relevant setting
-
xmr-pr
-
sarang
Would this have any effect on key management, or is just a simple check of the password?
-
fluffypony
just a check of the password
-
fluffypony
to make sure you're allowed to make that change
-
sarang
Right, but what's the threat model for this?
-
sarang
Either the spend key is accessible for making a transaction, or it isn't
-
fluffypony
sarang: I leave my computer unlocked and the GUI open, someone gets on my computer, disables the "ask for password" feature
-
fluffypony
and then empties the wallet
-
sarang
But is the spend key still accessible to the attacker anyway?
-
sarang
Or is this just a protection against casual attacks like you mention?
-
fluffypony
casual attacks, this isn't to guard against exfiltration from memory
-
sarang
Fair enough
-
sarang
As long as it doesn't make the user think there's protection that isn't really there
-
sarang
Like a warning that this doesn't replace the need for good device and key security
-
fluffypony
in the CLI we prompt for the password to change settings
-
fluffypony
sarang: this setting is on by default
-
sarang
yeah
-
sarang
I get what you're saying
-
fluffypony
so if the person turns it off they're choosing to lower their security
-
sarang
Seems reasonable as long as it's not a false sense of security about making transactions
-
moneromooo
It's hard to resist the urge to make sarcastic comments here, especially as I'm feeling extra sarcastic of late -_-
-
sarang
like what?
-
fluffypony
this is a safe space, moneromooo, you can be sarcastic here
-
fluffypony
:-P
-
moneromooo
Well, it feels like we'd end up with pages of US style lawyer speak on everything we do just because someone thinks someone else might shoot themselves in the foot
-
sarang
I don't mean warning on disabling the check
-
sarang
I mean is having the check a false sense of security
-
moneromooo
I get the "don't mislead people", but turning "ask for password" to "someone might think this protects them against malaria" (not actual wording, that's for effect) is a bit... meh ?
-
sarang
At any rate, if your device is compromised, you probably have many things to worry about
-
selsta
I guess if an attacker is on your system then you have lost anyway.
-
sarang
^ ya
-
moneromooo
I tend to like defense in depth. Even if a layer is not perfect, it tends to stop some percentage of attacks. Enough layers, and you end up stopping a fair amount, even if each layer has large caveats.
-
moneromooo
Sure, you always have this APT who knows their way and will not be stopped by any layer, but that doesn't mean the layers aren't useful against others.
-
selsta
right that’s why we ask for the password by default when viewing the seed or doing a tx
-
moneromooo
I do realize that, to some extent, this is just throwing stuff against the wall and hoping it sticks, which is kinda the antithesis of a threat model :)
-
fluffypony
Craig Wright blames APTs for everything
-
fort3hlulz
No existing issues with the GUI in Ubuntu with connecting to the integrated monerod, right?
-
fort3hlulz
Working with the Locha Mesh guys and they're having some issues but I don't have an Ubuntu desktop to test with right now
-
dsc_
GUI worked OK for me when I tried it last week or so, alltho that might have been version 15.x
-
dsc_
On Ubuntu, that is
-
fort3hlulz
Thanks
-
fort3hlulz
Im asking for the specific error but havent gotten it yet
-
fort3hlulz
Something about SSL
-
dsc_
best to also ask for `uname -a` and `cat /etc/lsb-release`
-
fort3hlulz
Will do!
-
dsc_
and the GUI mode they have chosen :)