[Popcon-developers] Bug#292163: Wrong permissions on /etc/popularity-contest.conf

Thomas Wana Thomas Wana <greuff@debian.org>, 292163@bugs.debian.org
Tue, 25 Jan 2005 15:12:46 +0100


Package: popularity-contest
Version: 1.26
Severity: minor

Hi,

the FAQ states:

Q) What are the privacy consideration for popularity-contest ?

A) Each popularity-contest host is identified by a random 128bit uuid
   (MY_HOSTID in /etc/popularity-contest). This uuid is used to track
   submission issued by the same host. It should be kept secret.

Indeed, the permissions on /etc/popularity-contest.conf (this is a typo
btw. in the FAQ) are:

neptun:~# ls -l /etc/popularity-contest.conf
-rw-r--r--  1 root root 357 Jan 25 15:04 /etc/popularity-contest.conf

which makes it world readable. The permissions should be adjusted.

Thanks,
Tom

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)
Kernel: Linux 2.6.10
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)

Versions of packages popularity-contest depends on:
ii  debconf                       1.4.30.11  Debian configuration management sy
ii  dpkg                          1.10.25    Package maintenance system for Deb
ii  postfix [mail-transport-agent 2.1.5-4    A high-performance mail transport 

-- debconf information:
  popularity-contest/hostid-failed:
* popularity-contest/participate: false