Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Links Detection #88

Open
smaragdus opened this issue Jan 3, 2020 · 2 comments
Open

Links Detection #88

smaragdus opened this issue Jan 3, 2020 · 2 comments

Comments

@smaragdus
Copy link

It would be extremely convenient (at least for me) if EncryptPad could detect URL links and mail links, example:

AkelPad 4 6 0 - 2020-01-03 - links - 002

My encrypted files often contain URL and mail links and if EncryptPad could detect them it would be easier to open these links in default web browser and in default mail client via double click or via CTRL+click.

@evpo
Copy link
Owner

evpo commented Jan 18, 2020

URL links in encrypted media are source of vulnerability. If sensitive information for one reason or another is recognised as an URL or follows a link in a dangerous way, it's going to be sent to the browser and the internet.

If this functionality is implemented, the user should be made aware of the risks involved. It may be safe for some files but dangerous for others. Probably one global setting is not ideal.

@smaragdus
Copy link
Author

smaragdus commented Jan 18, 2020

@evpo

I generally agree with you yet I suppose that users using such a program would know what they are doing. For example EncryptPad may be used for storing log-in credentials and a file may contain data in this pattern:

  • URL
  • User Name
  • Password
  • Note

In this case the sensitive data is not the URL but the user name and the password.

Another example- EncryptPad may also be used for storing contact details and a file may contain data in this pattern:

  • Name
  • Phone
  • Mail
  • Website

In this case the most sensitive data is the phone number and the mail address. Yet opening mail client directly from EncryptPad via mailto: link doesn't seem to be a huge security risk to me. Neither does opening a website link directly from EncryptPad.

If links detection is implemented it may be disabled by default. At least for me such a feature would be a huge improvement and a great convenience as it would seriously cut down the need to copy and paste.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants