Ticket #1373 (reopened Feature request)
[Security] Passwords saved as plain text
| Reported by: | greg_grossmeier | Owned by: | |
|---|---|---|---|
| Priority: | normal | Component: | FileZilla Client |
| Keywords: | Cc: | greg_grossmeier, codesquid | |
| Operating system type: | Operating system version: |
Description
Originally reported on Launchpad.net:
https://launchpad.net/bugs/202114
(sections are individual comments)
============
Passwords saved as plain text in ~/.filezilla/sitemanager.xml for fielzilla 3.0.0-0ubuntu1 on gutsy.
Password should be stored encrypted so that it is more protected to abuse.
============
The .filezilla directory itself is mode 700, so no one can read the plaintext passwords. That said, it would be a good idea for filezilla to use the Gnome Keyring instead of storing plain text passwords.
============
Confirmed on Hardy (filezilla 3.0.7.1-0ubuntu2)
Change History
Note: See
TracTickets for help on using
tickets.
