Skip to content

The digital town square for the concert band community.

Connect with local ensembles, trade repertoire insights, and keep the pulse of the wind band world.

  • Holy shit, Microsoft.

    World infosec facepalm clowncar
    29
    0 Votes
    29 Posts
    0 Views
    David Chisnall (*Now with 50% more sarcasm!*)D
    @kaidenshi @KF0UNK It's been ages since I looked at Firefox's password storage and that was before they moved to a multi-process architecture. Back then, a JavaScript sandbox escape could leak all passwords. From a quick skim of their docs, they encrypt the passwords on disk. It looks as if protecting the key that they're encrypted with from an attacker with local filesystem access requires you to set a primary password (which is presumably hashed and fed to a KDF to generate the keys), but that key will be in memory for at least one process.