I've set-up Fido2 u2f in /etc/pam.d/cosmic-greeter so that I can login and unlock my session with my yubikey.
It works fine.
But since then, if my key is plugged in, and then I lock the session : the password field is pre-filled with my actual password.
As a result it can be displayed !
(unlock fails because a touch of the key is awaited, but anyway, the password is compromised)
Using latest 1.9.0 packages, running PopOS 24.04.
Security "workaround" : manually empty the field when session is locked but ... that's kind of ridiculous, right ;)
I've set-up Fido2 u2f in
/etc/pam.d/cosmic-greeterso that I can login and unlock my session with my yubikey.It works fine.
But since then, if my key is plugged in, and then I lock the session : the password field is pre-filled with my actual password.
As a result it can be displayed !
(unlock fails because a touch of the key is awaited, but anyway, the password is compromised)
Using latest 1.9.0 packages, running PopOS 24.04.
Security "workaround" : manually empty the field when session is locked but ... that's kind of ridiculous, right ;)