How secure is ProtectedData.Protect (DPAPI)?

后端 未结 3 2072
执笔经年
执笔经年 2020-12-15 19:45

Suppose someone gets access all of my hard disk, I guess the weak spot would be my windows password. Without knowing/being able to retrieve that, the data should be pretty m

3条回答
  •  鱼传尺愫
    2020-12-15 20:18

    See this article on DPAPI Security. Basically, it is as secure as your Windows password -- if your password is reset by an administrator, the decryption key will be lost. The major attack vectors you'll need to look at are:

    • Password disclosure: "shoulder surfing", sticky notes, etc.
    • Capture of the computer's accounts database and the use of a password cracker
    • Online attack by "drive-by download", removable media AutoPlay, etc.
    • Capture of a password reset disk, if you've made one
    • Physical installation of a key-logging device or other "bug"

提交回复
热议问题