Re: reveal password fix needed

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Dave (Nobody_at_Nowhere.Com)
Date: 12/03/04


Date: Fri, 3 Dec 2004 15:03:20 -0000

Martin

Bonj is dead right, another point is that except in exceptional
circumstances no program should ever store a password. The secure way is to
create a non-reversable hash of the password, store that and then do the
same with what's entered and compare the 2.

Dave.

"Bonj" <Bonj@discussions.microsoft.com> wrote in message
news:B7837DF9-E82C-4BBF-977E-495BC3DA01F9@microsoft.com...
> The point of displaying it as asterisks is not to hide it from another
> program on your computer - it's only to hide it from someone looking over
> your shoulder.
>
> A program running on your computer could glean it anyway by monitoring the
> keys pressed on the keyboard.
>
>
> "Martin Nemzow" wrote:
>
>> Passwords hidden by asterisks in VB and even within Windows can be
>> revealed
>> in full with API call SendMessage among other methods since messages
>> within
>> Windows are not secured in anything other than plaintext unlike trusted
>> systems. Even if the password is encrypted after entry, the password can
>> be
>> intercepted through the system messaging traffic before it gets
>> encrypted.
>>
>> This is not good. Has anyone a solution to this security flaw?
>>
>> Marty Nemzow
>>
>>
>>



Relevant Pages

  • Re: Password manager
    ... You can try CASA from Novell ... This application provides secure ... store which can be consumed by other applcations to store the secret ... There is product called SecureLogin from Novell for Windows which is ...
    (Security-Basics)
  • Re: Where I can store my password on Win 2k?
    ... You could look into using the DPapi (depending on what ... Writing Secure Code book of M. Howard. ... Microsoft MVP (Windows Security) ... > In Windows 2000 operating system, where I can store the data secured? ...
    (microsoft.public.win2000.security)
  • Re: The Myth of the secure Mac
    ... >>> secure than Home. ... Though this really has nothing to do with security. ... >>> I, on the other hand, was speaking about overall Windows security, not ... I do believe that Microsoft could adjust their prices for the ...
    (comp.sys.mac.advocacy)
  • Re: Any Way to Run Windows 2000 From Read-Only CD?
    ... Your point regarding infecting the computer during runtime when the disk is ... Now, regarding UNIX versus Windows, I try to have a balanced view. ... administrator can isolate those and secure them. ...
    (microsoft.public.windows.server.security)
  • Re: migrating from Win2K to XP?
    ... > secure since not too many users are out there and perhaps not too many ... magically install themselves on anyone's computer. ... reliable and up-to-date antivirus software, ... Multibooting with Windows 2000 and Windows XP ...
    (microsoft.public.windowsxp.basics)