Moon Software Forum
Moon Software Forum
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Discussion Forums
 Password Agent
 Password Agent automation
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

Automate
Member

4 Posts

Posted - 16 October 2017 :  15:20:14  Show Profile  Reply with Quote
Hi,

I have two question regarding the Password Agent and automating some tasks:

- Is it possible to change the master password for a password file using a script? E.g. if I have 50 password files with the same master password and want to change the master password for all 50, I don't want to do that manually.

- Is it possible to retrieve a specific password from a password file using scripts or another form of automation (as long as it isn't GUI automation)?

Ahto/Moon Software
Developer

Estonia
1141 Posts

Posted - 16 October 2017 :  15:51:03  Show Profile  Visit Ahto/Moon Software's Homepage  Reply with Quote
There is no support for such automation as generally automation is undesired feature of such software, as it may allow an attacker to automate attacks and makes attacking your data easier.
Go to Top of Page

Automate
Member

4 Posts

Posted - 17 October 2017 :  09:42:53  Show Profile  Reply with Quote
quote:
Originally posted by Ahto/Moon Software

There is no support for such automation as generally automation is undesired feature of such software, as it may allow an attacker to automate attacks and makes attacking your data easier.


Hi,

Thank you for your reply.

I see what you mean, but I believe there would be several ways to prevent attacks from being effective or efficient and still be able to develop automation functionality.

For example, you could restrict the number of attempts to open a file. But there should be better ways as well.

By saying automation is an undesired feature, I feel like you're saying that the Password Agent isn't very useful for (large) companies that have many password files.
Go to Top of Page

Ahto/Moon Software
Developer

Estonia
1141 Posts

Posted - 17 October 2017 :  11:43:15  Show Profile  Visit Ahto/Moon Software's Homepage  Reply with Quote
Hello!

You should not use the same master password for multiple files, this is not good practice. If you follow that, your need for such automation diminishes. Yes, it may be convenient to have the same password for several files but generally you'd want to avoid that (if one user leaks the password, entire company is compromised).
Go to Top of Page

Automate
Member

4 Posts

Posted - 17 October 2017 :  12:25:06  Show Profile  Reply with Quote
quote:
Originally posted by Ahto/Moon Software

Hello!

You should not use the same master password for multiple files, this is not good practice. If you follow that, your need for such automation diminishes. Yes, it may be convenient to have the same password for several files but generally you'd want to avoid that (if one user leaks the password, entire company is compromised).


True, but that is just part of my request.

In light of automation, we'd also like to be able to retrieve specific passwords from a password file, because we don't want plaintext passwords in our automation tool.

If the password is changed due to a password policy, the automated tasks no longer work. Therefore it would be great if we could dynamically get passwords from a password file, so we can change the password without interrupting automated tasks.
Go to Top of Page

Ahto/Moon Software
Developer

Estonia
1141 Posts

Posted - 17 October 2017 :  15:53:51  Show Profile  Visit Ahto/Moon Software's Homepage  Reply with Quote
How you imagine the automation should work? Don't you need to pass master password of your data file in plain text to get some data from given database?
Go to Top of Page

Automate
Member

4 Posts

Posted - 17 October 2017 :  15:56:27  Show Profile  Reply with Quote
quote:
Originally posted by Ahto/Moon Software

How you imagine the automation should work? Don't you need to pass master password of your data file in plain text to get some data from given database?


No, I don't.

For example, if I were to use Powershell, I'd generate SecureString of the master password only once and then use the SecurityString in my script. That would have to be supported by the Password Agent. But even if it wouldn't, I could decrypt the SecureString in my script to plain text and as long as the decrypted password isn't actually printed somewhere, it has no impact on security.
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Moon Software Forum © Copyright 1996-2011 Moon Software Go To Top Of Page
Snitz Forums 2000