4 ms·
>The password is encrypted using CryptProtectData so to get the plain text it uses the function CryptUnprotectData. How does that work? Doesn’t it need the adm
by vadansky 8y ago
>The password is encrypted using CryptProtectData so to get the plain text it uses the function CryptUnprotectData.
How does that work? Doesn’t it need the admin password, or are Chrome credentials just sitting around in a really easy to decrypt format?
- kevindqc 8y ago> The CryptProtectData function performs encryption on the data in a DATA_BLOB structure. Typically, only a user with the same logon credential as the user who encrypted the data can decrypt the data. In addition, the encryption and decryption usually must be done on the same computer. For information about exceptions, see Remarks. https://docs.microsoft.com/en-us/windows/desktop/api/dpapi/nf-dpapi-cryptprotectdata https://docs.microsoft.com/en-us/windows/desktop/api/dpapi/n... If you can execute code on the computer (as the user), you can decrypt the credentials. Scary how easy it is to steal it all :(
- carterage 8y agoSo... fundamentally, encrypting data on the very same machine that retains the related keys, is tantamount to simply encoding the data in plaintext form without any real protection, yes?
- buckminster 8y agoIt's slightly better than that. You can't decrypt the data when the user isn't logged in.
- wiz21c 8y agobah, if one can install a password stealing program, then he can as well install a key logger. With both of those, you become virtually transparent.
- Fnoord 8y ago> If you can execute code on the computer (as the user), you can decrypt the credentials. The problem is that programs gain too much privileges they do not need (yet) without consent from the user. This kind of attack wouldn't work on Qubes OS, a well configured SELinux, or a well configured capability-based OS.