Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

API key should shown as dots, when pasted into input field #34

Closed
mpagels opened this issue Nov 4, 2020 · 1 comment
Closed

API key should shown as dots, when pasted into input field #34

mpagels opened this issue Nov 4, 2020 · 1 comment
Labels
enhancement New feature or request

Comments

@mpagels
Copy link

mpagels commented Nov 4, 2020

Is your feature request related to a problem? Please describe.
When I paste my piHole API key in the extension settings the key stays visible in plaintext for all other users who might using my browser and visiting the extension setting section. And everybody is able to copy/paste the key. I think this is a big security concern.

Describe the solution you'd like
I think the solution to the issue is, to change the type of the input field to "password", so that the api key is shown as dots and to stop the possibility to paste the key out of the form.

@mpagels mpagels added the enhancement New feature or request label Nov 4, 2020
@badsgahhl
Copy link
Owner

badsgahhl commented Nov 4, 2020

Mhh, I will think about it, but this is basically 'security by obscurity'.

Everybody in your network can sniff for the API Key, because the requests to the pihole are not secured.
And if someone has access to your pc or browser, every security mechanism in a chrome extension can be exploited, because there are no severs securing it.

But nevertheless I will make some thoughts about that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants