|
|
|
|
|
by tptacek
3815 days ago
|
|
All password managers store plain text passwords. That's literally a requirement for them to work at all. I'm not sure this is what you mean to say, because, obviously, good password managers don't store passwords in cleartext. |
|
So when people complain about password managers storing plain text (as opposed to hashing) they're barking up the wrong tree, it is a necessary evil.
You just want to see them encrypt those plain text passwords so that offline recovery is harder. That's what both Firefox's master password, CryptProtectData() for Chrome/IE, and the key-chain in OS X provide.