Disable WebDAV password view
When setting up WebDAV sync, next to the password is the small eye symbol which allows you to view the entered password. Anyone opening Zotero on my device could easily grab my password this way. Might there be a way to disable the possibility to view the entered password after sync is set up successfully?
Best, GN
Best, GN
-
dstillman Zotero Teamedited 21 days agoThe eye button comes from the underlying Firefox platform on all password fields. We could look into trying to hide that after successful sync setup, but having it there is really more honest — you should generally assume that someone with access to your unlocked OS account has access to your passwords, unless they're in a locked password manager. There's no way Zotero sync credentials could be truly secure unless you were prompted for a password on every sync. And even then, someone with access to the computer could change the network/certificate settings and capture network traffic, inspect process memory, etc. Don't let people use your computer unless you trust them!
-
WalccManfair enough, while I indeed use a locked password manager, your points are valid. I'll just set up a guest login
Upgrade Storage