View Single Post
Old 02-12-2015, 12:05 AM   #3718
JimmXinu
Plugin Developer
JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.JimmXinu ought to be getting tired of karma fortunes by now.
 
JimmXinu's Avatar
 
Posts: 7,043
Karma: 4604637
Join Date: Dec 2011
Location: Midwest USA
Device: Kobo Clara Colour running KOReader
Quote:
Originally Posted by kovidgoyal View Post
There is no secure way to reversibly store a secret on disk against an attacker that can run local code.
...
I agree. Which is why I've been reluctant to add this feature despite it's obvious utility.

However, I hadn't really thought about the fact calibre can already be holding onto your email user/pass for sending email, setting a precedent for it.

Right now I'm considering giving additional options and letting the user decide between:
  1. Saving password in FFDL config (by library)
  2. Entering password once per session/library switch (same as last test version)
  3. Entering password everytime
  4. Not using email url fetching
JimmXinu is online now