4 ms·
There's nothing wrong with storing passwords in plaintext on the machine.
by staticassertion 5y ago
There's nothing wrong with storing passwords in plaintext on the machine.
- drdec 5y agoOne vulnerability in your browser allowing file system access and now all your passwords are known to the hacker. You run the wrong executable and there go all your passwords again, being uploaded to who knows where. But you 100% trust the authors of all the software you run and you know they would never be vulnerable to a sole chain attack a la SolarWind. Don't keep passwords you can't afford to be public in plain text in a predictable location on the file system.
- staticassertion 5y agoIn every single case you've described the attacker can: a) Already ready your passwords from memory/ webpages/ any other of the million ways b) Access your cookies and session tokens If the attacker is in a position to read the plaintext file off of the disk it really won't matter if it's encrypted. You're welcome to do so, I'm sure there are extremely niche scenarios where it may help, but it's not really worth mentioning imo.
- drdec 5y agoNot all of your passwords will be in memory. I don't know how you read a password from "webpages". Session tokens do not exist for websites you are not currently accessing. The password file will contain all the saved passwords, whether you are logged in or not.
- xboxnolifes 5y ago> I don't know how you read a password from "webpages" When you enter your password to login.
- staticassertion 5y ago> Not all of your passwords will be in memory. They almost certainly will be, but the key will be if they aren't. > I don't know how you read a password from "webpages". Like a billion ways. Inject JS, log keys, install malicious extension, blah blah blah > Session tokens do not exist for websites you are not currently accessing. I'm just enumerating the billion ways that encryption is made pointless. > he password file will contain all the saved passwords, whether you are logged in or not. And the attacker can just access it lol Maybe in a world where full disk encryption wasn't ubiquitous you could talk about an offline attack, and you could tell me you share your computer with someone who's not tech savvy but is an asshole. But it's all gonna be pretty niche.