Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

登录密码明文储存不安全 #22

Closed
Ice9Coffee opened this issue Aug 4, 2020 · 1 comment
Closed

登录密码明文储存不安全 #22

Ice9Coffee opened this issue Aug 4, 2020 · 1 comment

Comments

@Ice9Coffee
Copy link

目前qq的登录密码明文储存在config中,在多用户共用服务器、服务器受外部攻击、所用软件有安全漏洞等情况下可能会被窃取。

考虑到自动重新登录的feature,建议:

  • 首次登录时询问密码
  • 使用密文存储密码
@undefined-moe
Copy link
Contributor

cqhttp能够解密表明其他软件也可以解密。
建议您优化 config.json 的文件权限。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants