Security vulnerability to user account and server side user data

Security vulnerability to user account and server side user data

Zoho stores unencrypted account information in the client side registry (e.g. zohopassword and zohousername keys under HKEY_USERS in Windows XP).

Does this constitute a serious and widespread security vulnerability - e.g. could a server side program steal this information and use it to access user accounts?

If not, what prevents this?

Even if server side theft of user account credentials is theroetically impossible, storing this data in plain ASCII format, and unencrypted, still represents a serious though less widespread vulnerability. This is because someone accessing a vacant terminal, or looking over a user's shoulder etc., would be able to steal their account login credentials.

Given the volume and sensitivity of the information stored in a user's account, this practice is a worryingly sloppy approach to the serious issue of protecting the user's account and server side data from unauthorised access.

Mark
http://www.markhughes.eu













    Access your files securely from anywhere

        Zoho Developer Community




                                  Zoho Desk Resources

                                  • Desk Community Learning Series


                                  • Digest


                                  • Functions


                                  • Meetups


                                  • Kbase


                                  • Resources


                                  • Glossary


                                  • Desk Marketplace


                                  • MVP Corner


                                  • Word of the Day



                                      Zoho Marketing Automation


                                              Manage your brands on social media



                                                    Zoho TeamInbox Resources

                                                      Zoho DataPrep Resources



                                                        Zoho CRM Plus Resources

                                                          Zoho Books Resources


                                                            Zoho Subscriptions Resources

                                                              Zoho Projects Resources


                                                                Zoho Sprints Resources


                                                                  Qntrl Resources


                                                                    Zoho Creator Resources



                                                                        Zoho Campaigns Resources


                                                                          Zoho CRM Resources

                                                                          • CRM Community Learning Series

                                                                            CRM Community Learning Series


                                                                          • Kaizen

                                                                            Kaizen

                                                                          • Functions

                                                                            Functions

                                                                          • Meetups

                                                                            Meetups

                                                                          • Kbase

                                                                            Kbase

                                                                          • Resources

                                                                            Resources

                                                                          • Digest

                                                                            Digest

                                                                          • CRM Marketplace

                                                                            CRM Marketplace

                                                                          • MVP Corner

                                                                            MVP Corner





                                                                              Design. Discuss. Deliver.

                                                                              Create visually engaging stories with Zoho Show.

                                                                              Get Started Now