Security Flaw -- password(s) revealed
Brought to you by:
hollow_
After a password is decrypted, it is displayed in the Account View page in plain HTML. This means the page and, therefore, the password are cached on the local computer. It would be easy to use a browser's history or even just the back button to view the password. I believe this is a major security flaw, but I'm not quite sure how to fix it.
Logged In: YES
user_id=1761957
Originator: NO
if the page was served over SSL it would help...
Logged In: YES
user_id=1293131
Originator: NO
You can add a meta tag to prevent caching (quick google search: http://www.i18nguy.com/markup/metatags.html\). be warned, IE 6 and below do not handle this well with out the update (http://support.microsoft.com/kb/323308 and http://support.microsoft.com/default.aspx/kb/937479\)
Can the browser receive instructions to do not cache the page?