Printed Config Shows All Passwords
- G4POP
- Log4OM Alpha Team
- Posts: 11587
- Joined: 21 Jan 2013, 14:55
- Location: Burnham on Crouch, Essex UK
Re: Printed Config Shows All Passwords
It is necessary to have the plain English text of the user names and passwords but I can see the problem for clubs, perhaps we should password protect use of the 'Print Config' button?
73 Terry G4POP
- IW3HMH
- Site Admin
- Posts: 2988
- Joined: 21 Jan 2013, 14:20
- Location: Quarto d'Altino - Venezia (ITA)
- Contact:
Re: Printed Config Shows All Passwords
Interesting point... i never thought about that...
Adding to the list... nice one
Adding to the list... nice one
Daniele Pistollato - IW3HMH
- G4POP
- Log4OM Alpha Team
- Posts: 11587
- Joined: 21 Jan 2013, 14:55
- Location: Burnham on Crouch, Essex UK
Re: Printed Config Shows All Passwords
If we did that it makes the 'Print config' of no value, it is there so that users have a record of their user names and passwordsexl46 wrote:I'd suggest encrypting the passwords, and not listing them when the config PDF is generated..
Recently we started saving a backup of the config file with the normal backup so perhaps the best idea is to REMOVE the print config facility altogether. This will save a lot of programming time and resolve the issue.
Whilst we are at it the 'Reset Config' button has caused some accidental configuration deletions in the past perhaps we should remove that also?
73 Terry G4POP
- IW3HMH
- Site Admin
- Posts: 2988
- Joined: 21 Jan 2013, 14:20
- Location: Quarto d'Altino - Venezia (ITA)
- Contact:
Re: Printed Config Shows All Passwords
Hi,
Log4OM is not "structured" to ensure military-grade password encryption for passwords.
We started from the "single user" point of view, where saving passwords (and let users export them in PDF plain text) could be useful for users that set their configuration once and never change it for ages, except in case of computer crash or something like.
Having an import/export function for single profiles can be simple to do, but users must remind to remove their profiles when leaving the station. Another option is to save both config.xml and communicatorconfig and delete them from backup folders and from setting folders.
Again, a function that could be very annoying for 99.9% of users.
I will add a minimal "security" feature on PDF export but other implementations are interesting but not of immediate realization. I keep the idea on desk, anyway
Log4OM is not "structured" to ensure military-grade password encryption for passwords.
We started from the "single user" point of view, where saving passwords (and let users export them in PDF plain text) could be useful for users that set their configuration once and never change it for ages, except in case of computer crash or something like.
Having an import/export function for single profiles can be simple to do, but users must remind to remove their profiles when leaving the station. Another option is to save both config.xml and communicatorconfig and delete them from backup folders and from setting folders.
Again, a function that could be very annoying for 99.9% of users.
I will add a minimal "security" feature on PDF export but other implementations are interesting but not of immediate realization. I keep the idea on desk, anyway
Daniele Pistollato - IW3HMH
Re: Printed Config Shows All Passwords
I would leave things as they are. I am very happy that the passwords are available in plain text. I was happy to discover that they are by coming across this thread.
You've never known happiness until you're married; but by then it is too late.