[tor-bugs] #3064 [Vidalia]: Vidalia stores ControlPassword as plaintext

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Sun May 1 17:48:21 UTC 2011


#3064: Vidalia stores ControlPassword as plaintext
--------------------------+-------------------------------------------------
    Reporter:  tornewbie  |       Owner:  chiiph  
        Type:  defect     |      Status:  reopened
    Priority:  normal     |   Milestone:          
   Component:  Vidalia    |     Version:          
  Resolution:             |    Keywords:          
      Parent:             |      Points:          
Actualpoints:             |  
--------------------------+-------------------------------------------------
Changes (by arma):

  * status:  closed => reopened
  * resolution:  wontfix =>


Comment:

 It would be nice to have more of a solution here.

 Right now it is safer to use your Tor with a random password, since that
 password never gets written to disk. And I bet most users don't realize
 that.

 One answer might be to try to make it clearer to the user what security
 tradeoff he's making by setting a password -- e.g. some sort of "what are
 the security implications?" help box nearby.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/3064#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list