3 ms·
You're right. To me, it's not their use of (effectively) plaintext that is worrisome. It's that the developer characterizes base64 as "encryption", which tells
by orborde 15y ago
You're right. To me, it's not their use of (effectively) plaintext that is worrisome. It's that the developer characterizes base64 as "encryption", which tells me that they don't even understand the security implications. As an example of a non-worrying response, here's Pidgin's documentation on their choice not to encrypt passwords: http://developer.pidgin.im/wiki/PlainTextPasswords http://developer.pidgin.im/wiki/PlainTextPasswords
- tomaspollak 15y ago"Having our passwords in plaintext is more secure than obfuscating them precisely because, when a user is not misled by a false sense of security, he is likely to use the software in a more secure manner." I must say I don't agree with the Pidgin devs. They think that the user will use the software in a more secure manner because they assume he's aware that the password is stored in cleartext. That may be true on 1% of the cases. But the other 99% of the people probably don't have a clue, and they wouldn't even know where to find the accounts.xml file in the first place.
- cookiecaper 15y agoI'm not convinced that the appearance of that terminology in the file means the developer is unaware of the difference between encoding and encrypting something. I think we all know the meanings of some words, but continue to misuse them out of convenience and/or habit. It can be difficult to break such a habit. Perhaps you should simply include a patch that will reword the file in the correct manner. :)