3 ms·
The files in question[1] are only readable by the current user. That is the default for files stored in the user's folder. I just checked my own installation an
by Genbox 4y ago
The files in question[1] are only readable by the current user. That is the default for files stored in the user's folder. I just checked my own installation and the files does have the correct permissions.
Having tokens in clear text is not a serious security issue as long as the files cannot be accessed by anyone else.
The best way of storing credentials today is to either:
A. Use asymmetric cryptography and store the private keys in a non-exportable format like the Trusted Platform Module.
B. Use an API like the Data Protection API in Windows and store the secrets under "User scope". This encrypts the secrets with the user's logon password.
Only solution A above protects against malware running as the current user, however, the solution is also not very portable and technically difficult to maintain across platforms.
There is no way Microsoft (or any other software vendor on the market today) can truly protect against credential stealing if malware is running in the context of the user. The exception is solution A above, but even then the attacker would have brief access to the remote systems as long as the user is concurrently using those systems.
[1] https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens https://www.vectra.ai/blogpost/undermining-microsoft-teams-s...
- JohnFen 4y ago> Having tokens in clear text is not a serious security issue as long as the files cannot be accessed by anyone else. Conceptually true. However, you cannot guarantee that the files can't be accessed by anyone else. I think that storing any critical data in cleartext is a Bad Thing because it eliminates a layer in a layered defense stance, and layered security is always desirable.