Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> OK, that is incorrect. DPAPI is supposed to protect from this by deriving encryption key from your password.

That's the point: DPAPI is (deliberately) bypassed by TBAL, by storing the necessary info from the user's password to decrypt the DPAPI key after reboot.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: