Skip to content

Passwords stored in clear text #178

@szapp

Description

@szapp

To my surprise I found that my credentials are stored in clear text in %AppData%\g-node\WinGIN\UserCredentials.json!

Although - in an ideal case - no one should have access to my personal folder, I don't think that's very secure. Especially since the web interface even offers measures like TFA.

Would it be possible to use more secure methods, like the Windows Credential Manager?

Alternatively, and as a quick workaround, would it be possible to offer a setting to not store my password but to prompt for it (at the cost of no background updates)? I'd rather abstain from using the WinGIN until there is a solution.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions