Is it possible to prevent password extraction from LaZagne?
-
I just saw https://github.com/AlessandroZ/LaZagne can extract password from Vivaldi, is it possible to prevent this, even with encrypted Vivaldi passwords?
-
@saudiqbal On Windows the stored passwords are encrypted using DPAPI, see:
https://forum.vivaldi.net/topic/41352/windows-encrypted-password-and-data-store-dpapiThis basically means any application run by a logged-in user account will be able to decrypt these stored passwords. This also means keeping your account safe and not letting others "borrow" it. The fact that Vivaldi prompts for a password is only for show.
See for instance the tool ChromePass which can easily decrypt Vivaldi passwords.
Personally I think it's good enough - if a user cannot keep their user account safe, there's not much point in additional layers of security. But a master password might be a good idea to implement in Vivaldi for those of a more paranoid persuasion
For Mac/Linux passwords are stored differently, using key databases so it might be different.
-
Password recovery tools are very useful when you have a system that needs recovering or you want to backup your important info easily.
Tools like this will be flagged as malware or potentially unwanted programs. Usually to use them you will have to override the AV.
Even if a master password is used, many password recovery tools will just allow you to present that password and unlock.
-
Ppafflick moved this topic from Security & Privacy on