Bugtraq mailing list archives
Re: ZipTorrent 1.3.7.3 Discloses Proxy Passwords to Local Users
From: Nicholas Knight <nknight () runawaynet com>
Date: Fri, 26 Aug 2005 15:50:39 -0700
Nick Boyce wrote:
Surely this is just another rehash of the same old debate that appears here every now and then - the conclusion will always be that stored passwords are inherently vulnerable. They can be obfuscated as much as you like, but it only needs one successful piece of R&D to render the whole obfuscation scheme useless for everybody.See http://marc.theaimsgroup.com/?t=92420089800002&r=1&w=2 http://marc.theaimsgroup.com/?t=94570694700003&r=1&w=2 for a couple of useful Bugtraq debates on this topic. [both in 1999 ... was that _really_ the last time this came up ?]
Good grief. Are DOS and Win9x concepts really so burned into people's brains that they can't recognize the proper solution for storing data where other users on a system can't get to it?
These aren't the days of single-user desktop operating systems anymore, people. You don't need inherently insecure obfuscation techniques to hide data, you just have to store it where it friggin' belongs -- IN THE USER'S HOME DIRECTORY.
Current thread:
- ZipTorrent 1.3.7.3 Discloses Proxy Passwords to Local Users kozan (Aug 23)
- Re: ZipTorrent 1.3.7.3 Discloses Proxy Passwords to Local Users Allen Parker (Aug 24)
- Re: ZipTorrent 1.3.7.3 Discloses Proxy Passwords to Local Users Nick Boyce (Aug 25)
- Re: ZipTorrent 1.3.7.3 Discloses Proxy Passwords to Local Users Nicholas Knight (Aug 27)
- Re: ZipTorrent 1.3.7.3 Discloses Proxy Passwords to Local Users Nick Boyce (Aug 25)
- Re: ZipTorrent 1.3.7.3 Discloses Proxy Passwords to Local Users Allen Parker (Aug 24)