After a password is decrypted, it is displayed in the Account View page in
plain HTML. This means the page and, therefore, the password are cached on
the local computer. It would be easy to use a browser's history or even
just the back button to view the password. I believe this is a major
security flaw, but I'm not quite sure how to fix it.
Nobody/Anonymous
None
None
Public
|
Date: 2009-04-16 16:26 Can the browser receive instructions to do not cache the page? |
|
Date: 2008-05-29 18:26
|
|
Date: 2008-03-31 09:19
|
| Field | Old Value | Date | By |
|---|---|---|---|
| priority | 5 | 2007-11-16 15:21 | selvirino |
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use