Jump to content
Not connected, Your IP: 3.238.7.202
unit13

Suggestion: Hash saved login info (AirVPN.xml)

Recommended Posts

Eddie client saves login and password information in AirVPN.xml as cleartext!

 

I am suggesting this information be hashed when saved, if possible.

 

<?xml version="1.0" encoding="utf-8"?>
<eddie>
  <options>
    <option name="login" value="your-saved-email-address@sample-email-address.com" />
    <option name="password" value="your-AirVPN-password-in-cleartext" />
    <option name="remember" value="True" />

...

 

Share this post


Link to post

Maybe I'm not thinking of every possible situation but if a malicious somebody has access to that xml file then it's already over for you - they've gained access to your machine.   My VPN username and password would be way down the list of worries. 

Share this post


Link to post

 

Hi!

 

Referencing Windows version.

I just noticed: Why is the AirVPN password in the AirVPN.xml saved in plain text. Is there a chance to save it hashed, at least?

 

 

Regards, giga

 

Hello!

 

No, that's not planned at the moment. To save it encrypted in a safe way you should enter a master password (like you do with browsers) that is not stored anywhere, so it would be totally identical to as it is now when you don't keep "Remember" ticked. Different methods can be invented and made secure regardless of client program source code exposure but what would the point be...?

 

Kind regards

AirVPN Support Team


» I am not an AirVPN team member. All opinions are my own and are not to be considered official. Only the AirVPN Staff account should be viewed as such.

» The forums is a place where you can ask questions to the community. You are not entitled to guaranteed answer times. Answer quality may vary, too. If you need professional support, please create tickets.

» If you're new, take some time to read LZ1's New User Guide to AirVPN. On questions, use the search function first. On errors, search for the error message instead.

» If you choose to create a new thread, keep in mind that we don't know your setup. Give info about it. Never forget the OpenVPN logs or, for Eddie, the support file (Logs > lifebelt icon).

» The community kindly asks you to not set up Tor exit relays when connected to AirVPN. Their IP addresses are subject to restrictions and these are relayed to all users of the affected servers.

 

» Furthermore, I propose that your paranoia is to be destroyed. If you overdo privacy, chances are you will be unique amond the mass again.

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image

×
×
  • Create New...