3 ms·
Why account passwords are stored on plaintext after the wizard? How do you encrypt them while configuring?
by sulfastor 7y ago
Why account passwords are stored on plaintext after the wizard? How do you encrypt them while configuring?
- Sir_Cmpwn 7y agoman aerc-imap for details, you can specify an external command to run. The creds file is chmod 600, and most other email clients (e.g. thunderbird) are also storing your creds in plaintext - it's just less obvious cause they put them in sqlite or something.
- necovek 7y agoUnless you are willing to provide a decryption key on every "check my email" call (eg. every 5 minutes), an email client (or well, anything requiring frequent reauthorization) virtually has to have it in "plain text" (or any obfuscated form which is equivalent to plain text). Workable alternatives are to store the decryption key in memory for the runtime of the program (eg. using login keyrings or per-app logic). If you encrypt your $HOME or your entire disk, storing it in plain text achieves roughly the same level of protection (eg. decryption key is in the memory).