Sxipper secure?

Sxipper is an awsome and convenient Firefox tool that makes life simpler and at the same time claims to be secure. Great isn’t it?

Sxipper claims:

Privacy – Sxipper protects your personal data by keeping it secure on your computer and retrieving it for you when you choose to share it online.

But when you enter Sxipper preference panel, you can click Show password, and whoops only a Yes to a question, and there is all your passwords:

Update: After some more playing around with firefox 3 I figured out that if you set a global master password on FF, Sxipper will use that. That’s not too bad. Clever. But what would be even better; if you could use Apple Keychain instead…

Let’s double check:

[sxipper2]$ find . | xargs strings | grep encrypted
{"id":"sxipper@sxip.com","version":"1.0","encrypted":true,"format":"json","type":"complete"}
{"id":"sxipper@sxip.com","version":"1.0","encrypted":true,"format":"json","type":"complete"}
MIIKtAQQ+AAAAAAAAAAAAAAAAAAAATAUBggqhkiG9w0DBwQIs3411U+Vi30EggqIzN0+8aIy5qK/2B7xHL40XlUEQYeEP19jGBPj/VN/hdOJ+94hsluBay5G3tLU6Cr0m78mchijmOA0/0e7zQ2eVN/sy3/FOzduBk4MBcfk2VaRdvhCik6TVo4inDjWRwMIioxSNp4RnNGxB2mH8I18qURi0W0WsrONPscnLlUdp5jnWEeQnu/dXQEIcUKpC8G/QQL6gyPaFG13HeCMoKypGXhuzj1ft1JMlIpKwPjLRuQGjWLIqk/M8pYfGnWglmB[snipp]

Looks encrypted to me. (After some base64 decoding)

Leave a Reply