Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Applications such as password managers may need to retrieve the original password in order to enter it into a third-party application. This is permitted even though it violates the guideline. The password manager is accessed by a single user and always has the user's permission to store his or her passwords and to display those passwords on command. Consequently, the limit to safety and security is the user's competence rather than the program's operation.

Related Guidelines

ISO/IEC TR 24772:2013

Insufficiently Protected Credentials [XYM]

MITRE CWE

CWE-256, Plaintext storage of a password

Bibliography

...