Menu

#461 Password is stored as plain text in the configuration file

areca-7.x
closed
nobody
3
2015-02-17
2012-10-17
Paul
No

The backup encryption password is stored as plain text in the settings xml file ('.bcfg')
I would like to see it stored encrypted to preserve the security of the backups.Thanks.

Discussion

  • SanskritFritz

    SanskritFritz - 2012-10-17

    If you check the backed up config file, you'll see that the password is not there. Areca only stores the password locally.

     
    • Paul

      Paul - 2012-10-17

      Okay I see that is the case however storing the password locally in plain text is still a security risk, especially on XP. I was very surprised to see it there. Anyone with access to the local machine could potentially see the passwords. My request is that the password be encrypted within the application and stored that way in the local config file as it seems that the encryption code is present in the software already. I am asking this as an enhancement to a great piece of software.

       
  • aventin

    aventin - 2013-08-21

    Hi

    This is available in v7.3.6

    Best regards

     
  • aventin

    aventin - 2013-08-21
    • status: open --> closed
     

Log in to post a comment.

MongoDB Logo MongoDB