You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
One thing I was surprised to discover is that Keychain does not encrypt the names corresponding to password entries; these are easily readable via strings or similar. This means that the websites the user accesses, and often related email addresses, can be trivially extracted from the login keychain:
One thing I was surprised to discover is that Keychain does not encrypt the names corresponding to password entries; these are easily readable via
strings
or similar. This means that the websites the user accesses, and often related email addresses, can be trivially extracted from the login keychain:This is retrospectively "obvious" since Keychain itself can read the name/titles without a password, but it might be worth noting in the guide.
The text was updated successfully, but these errors were encountered: