Web Server Password Encryption
I recently set up my Calibre library to use the web server feature so that I could access my library from anywhere, as well as give friends and family access to my books. I set it up such that it requires a username and password, mostly because I don't want someone random stumbling upon it and deleting all my books. Out of curiosity, I downloaded a database reader to open the server-users.sqlite file that is stored in %APPDATA%/calibre. I found that the passwords are stored in plaintext. It's not a huge deal because someone would have to get access to my computer to get those passwords, but it's probably something that should be addressed eventually.
Regards,
Vicendithas
|