Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[security] The default of Save History should be disabled #442

Open
attila-lendvai opened this issue Apr 10, 2024 · 0 comments
Open

[security] The default of Save History should be disabled #442

attila-lendvai opened this issue Apr 10, 2024 · 0 comments

Comments

@attila-lendvai
Copy link

attila-lendvai commented Apr 10, 2024

context

the basic idea of the clipboard is that it's an ephemeral storage, not readable by any app without explicit user action. as such, it often contains passwords and other sensitive information in its regular use. saving the history in clear text increases the attack surface in at least two ways:

  1. boot from a pen drive and steal the clipboard history (from any unencrypted installation, which is still too often the case).
  2. any app that has disk access can steal the passwords, even if it has no access to the clipboard.

request

please set the default value of the Save History setting to disabled to minimise any unintended exposure to these attacks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant