Quote:
Originally Posted by kovidgoyal
There is no secure way to reversibly store a secret on disk against an attacker that can run local code.
...
|
I agree. Which is why I've been reluctant to add this feature despite it's obvious utility.
However, I hadn't really thought about the fact calibre can already be holding onto your email user/pass for sending email, setting a precedent for it.
Right now I'm considering giving additional options and letting the user decide between:
- Saving password in FFDL config (by library)
- Entering password once per session/library switch (same as last test version)
- Entering password everytime
- Not using email url fetching