https://stackoverflow.com/questions/7859972/storing-credenti...
Not storing that kind of stuff will need prompts to re-enter it too.
https://stackoverflow.com/questions/7859972/storing-credenti...
Not storing that kind of stuff will need prompts to re-enter it too.
local storage can be read using JavaScript from the same domain if you control all the JS on the domain, then this shouldn't be a problem. But if any other code is executed (i.e. via injection), they will be able to access the local storage
Nobody here is saying that an attacker can easily access your domain's localstorage, but just expressing the sentiment that "storing plaintext passwords is bad in almost any case".
Just like you can store plaintext passwords in your application database, and theoretically they are safe, but if a bad guy gets in your users are screwed, not just on your site but on others.
http://i.imgur.com/zauv4sK.png
Your disk could be encrypted, but not everyone's will be. It's better to just localStorage as it was intended.
Plus if you introduce a bug later down the line, you might not prune older localStorage entries, meaning they will stay there for much longer than you want. AND the user may not revisit your site ever again after going offline, which doesn't give you an opportunity to prune it.