TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft Teams has been storing authentication tokens in plaintext

3 pointsby aruanavekarover 2 years ago

1 comment

akerl_over 2 years ago
This seems like just a true statement about all local apps, isn’t it? Teams integrates with email&#x2F;sharepoint&#x2F;etc, so the app needs a token that can access those things, and the app has to store the token such that it can be used for requests.<p>They could obfuscate the token by encrypting it, but a local attacker would still be able to read it because the local system would need to then store the decryption key somewhere; it’s turtles all the way down.<p>Slack has a similar failure mode, as do Chrome cookies and every other local app I’m aware of.