4 ms·
They could stick a hardware encryption chip into their products and with a proper crypto system could enable secure encryption even against an active attacker w
by Perdition 13y ago
They could stick a hardware encryption chip into their products and with a proper crypto system could enable secure encryption even against an active attacker with control of the OS. Even a password hash using a decent hash like bcrypt would be secure against an attacker with only user privileges.
Single byte XOR is just child's play, even if the "key" was only used once. They may as well have used ROT-13.
- deleted 13y ago[deleted]
- elliottcarlson 13y agoWhile this would be a better route for encryption, it wouldn't help older hardware receiving firmware updates - so a non-hardware route would be required.
- lstamour 13y agoHmm. To guard against an attacker with only user privileges, couldn't you simply mark the file as accessible only by root? ;-) That said, I'd say if you have user privileges in my router, I've bigger issues than wifi passwords and config files...
- Perdition 13y agoMany of the home router vendors have released firmware with stupid flaws like allowing the inbuilt webserver (running as root) to traverse up directories and thus allow the attacker to view config files. If the passwords were stored properly hashed then the attacker has to do a lot more work to recover the plain text.