Printed Config Shows All Passwords

General discussions about Log4OM features
Locked
User avatar
G4POP
Log4OM Alpha Team
Posts: 11585
Joined: 21 Jan 2013, 14:55
Location: Burnham on Crouch, Essex UK

Re: Printed Config Shows All Passwords

Post by G4POP »

It is necessary to have the plain English text of the user names and passwords but I can see the problem for clubs, perhaps we should password protect use of the 'Print Config' button?
73 Terry G4POP
User avatar
IW3HMH
Site Admin
Posts: 2988
Joined: 21 Jan 2013, 14:20
Location: Quarto d'Altino - Venezia (ITA)
Contact:

Re: Printed Config Shows All Passwords

Post by IW3HMH »

Interesting point... i never thought about that...
Adding to the list... nice one
Daniele Pistollato - IW3HMH
User avatar
G4POP
Log4OM Alpha Team
Posts: 11585
Joined: 21 Jan 2013, 14:55
Location: Burnham on Crouch, Essex UK

Re: Printed Config Shows All Passwords

Post by G4POP »

exl46 wrote:I'd suggest encrypting the passwords, and not listing them when the config PDF is generated..
If we did that it makes the 'Print config' of no value, it is there so that users have a record of their user names and passwords

Recently we started saving a backup of the config file with the normal backup so perhaps the best idea is to REMOVE the print config facility altogether. This will save a lot of programming time and resolve the issue.

Whilst we are at it the 'Reset Config' button has caused some accidental configuration deletions in the past perhaps we should remove that also?
73 Terry G4POP
User avatar
IW3HMH
Site Admin
Posts: 2988
Joined: 21 Jan 2013, 14:20
Location: Quarto d'Altino - Venezia (ITA)
Contact:

Re: Printed Config Shows All Passwords

Post by IW3HMH »

Hi,
Log4OM is not "structured" to ensure military-grade password encryption for passwords.
We started from the "single user" point of view, where saving passwords (and let users export them in PDF plain text) could be useful for users that set their configuration once and never change it for ages, except in case of computer crash or something like.

Having an import/export function for single profiles can be simple to do, but users must remind to remove their profiles when leaving the station. Another option is to save both config.xml and communicatorconfig and delete them from backup folders and from setting folders.
Again, a function that could be very annoying for 99.9% of users.
I will add a minimal "security" feature on PDF export but other implementations are interesting but not of immediate realization. I keep the idea on desk, anyway
Daniele Pistollato - IW3HMH
User avatar
G4DWV
Old Man
Posts: 445
Joined: 11 Sep 2014, 16:02

Re: Printed Config Shows All Passwords

Post by G4DWV »

I would leave things as they are. I am very happy that the passwords are available in plain text. I was happy to discover that they are by coming across this thread.
You've never known happiness until you're married; but by then it is too late.
Locked