4 ms·
I was wondering that myself, and just this moment tested it. Interestingly, I pressed cancel on the keyring dialog instead of entering a password.. everything s
by mrintegrity 3y ago
I was wondering that myself, and just this moment tested it. Interestingly, I pressed cancel on the keyring dialog instead of entering a password.. everything seems to work fine!? I can view saved passwords for wifi networks in gnome network manager, firefox passwords can be viewed in it's manager too. So what exactly does this system protect?
It seems I have either misunderstood it's functionality or it's completely broken. Is it literally only protecting the "login keyring", in which case what is the point when I can still login and seemingly do everything anyway?
In the gui "seahorse" I can view all openssh and gpg keys without having unlocked the login keyring.. very confused by this!
- oynqr 3y agoNetworkManager can save credentials for all users, which is probably your case, and the others don't use the system keyring by default.
- yrro 3y ago> I can view saved passwords for wifi networks in gnome network manager, These are stored system-wide, within NM's connection profiles (likely /etc/NetworkManager/system-connections/whatever.nmconnection). > In the gui "seahorse" I can view all openssh and gpg keys without having unlocked the login keyring This is unlocked when you first log in, or unlock your session (pam_gnome_keyring.so stashes the password when called from 'auth' and retrieves it & uses it to unlock the user's keyring when called from 'session'); but I don't believe the keyring is locked when the session is locked, only when the system suspends/hibernates.
- Karliss 3y agoOpenSSH keys have their own passwords. On my system there are a few things that are stored within login keyring: chromium safe storage for various electron based programs (Chromium itself, discord, vscode, unity hub), password or login token for Element (matrix client), svn password, login credentials for VM which was created using Gnome Boxes. All of which might be a software that you don't use or use in different configuration. But since I don't have a fingerprint reader i can't verify that those things wouldn't work when logging in without password. Edit: as a test I deleted the secrets stored by discord and Element, after restarting the programs both of them were able to login without reentering password. So while they are storing something within login keyring, it doesn't seem to be anything important, and actual credentials are stored elsewhere.