The person quoted in the article says admin access isn't required and to bolster this gives an example of someone with admin access being able to access the recall database. I'm confused.
The person quoted in the article says admin access isn't required and to bolster this gives an example of someone with admin access being able to access the recall database. I'm confused.
It's no wonder collecting this info is a priority. It will be a goldmine for dataminers with the right correlation. Sure right now it's not collected centrally but I'm sure sooner or later there'll be a quick "just click off this tiny T&C update before you continue" crossing our paths.
Also, it means that this confidential info is now in more places than one. It's no longer sufficient to encrypt a file and lay it on a usb stick in the safe.
And it's also there in centralised place ripe for the taking. Not even any need to scan the system to find valuable information.
That said, yeah, if the user interacts dumping saved passwords is trivial as well.