chrismiceli / daap-client

Automatically exported from code.google.com/p/daap-client
8 stars 4 forks source link

Password is shown as plain text in settings #84

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
App works flawless, but the password for a share is shown as true text in 
settings. It should normally be shown as ******. Are the passwords also saved 
as plain text?

Original issue reported on code.google.com by carlchro...@gmail.com on 21 Dec 2012 at 12:17

GoogleCodeExporter commented 9 years ago
Thanks for the compliment!  The password is stored in plain text and this was 
an intentional decision.  We should have made it more clear in the wiki, but 
the password for DAAP is completely insecure.  It is sent in plaintext using 
http in the url and this is part of the DAAP protocol, which we can't change.  
For this reason, we recommend not using a strong password.  Even if the 
password was secured, all the information streaming back and forth are also in 
plaintext.  Having the password appear in settings should be a reminder to not 
use anything that is considered secure, which people may use with another, more 
secure account like a bank account.

Original comment by michael.miceli88@gmail.com on 21 Dec 2012 at 4:00