Quantcast
Channel: Ignite Realtime: Message List
Viewing all articles
Browse latest Browse all 11413

Re: Is openfire & spark still being updated?

$
0
0

Hi Ferit,

 

i think that the encryption method in spark isn't that insecure as it seems to be. However, it could be better. For example spark could create its own secret key during the first start or you can change it and build your own spark.

 

But the problem will remain the same, because you have to store the secret key somewhere on your system, because you need to decrypt it. In fact, the a stored key is not a vulnerability because it can not be accessed remotely. If there is somebody who has access to your machine you are always in trouble, because it is necessary that you can trust your computer. Otherwise you will need some kind of asymmetric encryption using a public/private keys to store server specific credentials.

 

Btw there are a lot of "password encryptors" out there for google chrome, firefox, pidgin, trillian, whatever... but they all need (admin) privileges on your machine.

 

greetings


Viewing all articles
Browse latest Browse all 11413

Trending Articles