Menu ▾ ▴

#2 Security Flaw -- password(s) revealed

open
nobody
None
9
2007-11-16
2007-11-16
selvirino
No

After a password is decrypted, it is displayed in the Account View page in plain HTML. This means the page and, therefore, the password are cached on the local computer. It would be easy to use a browser's history or even just the back button to view the password. I believe this is a major security flaw, but I'm not quite sure how to fix it.

Discussion

  • selvirino

    selvirino - 2007-11-16
    • priority: 5 --> 9
     
  • GingerDog

    GingerDog - 2008-03-31

    Logged In: YES
    user_id=1761957
    Originator: NO

    if the page was served over SSL it would help...

     
  • leprasmurf

    leprasmurf - 2008-05-29

    Logged In: YES
    user_id=1293131
    Originator: NO

    You can add a meta tag to prevent caching (quick google search: http://www.i18nguy.com/markup/metatags.html\). be warned, IE 6 and below do not handle this well with out the update (http://support.microsoft.com/kb/323308 and http://support.microsoft.com/default.aspx/kb/937479\)

     
  • Nobody/Anonymous

    Can the browser receive instructions to do not cache the page?

     

Log in to post a comment.