If credentials are saved in a location controlled by mRemoteNG (ie, xml file) then setting a custom password should be mandatory. If a user fully encrypts their connections file, then a custom password will also be required.
Currently, the default is to use a hard coded default password unless the user specifies a different one. This makes decryption trivial and is poor practice.
Related to #306
Related to #208
This should be bumped to a very high priority!
has this been fixed? Any good practice to avoid offline decryption of password?
@fela15 No its not fixed by default. You need to make some changes to the configuration of mRemoteNG. Such as enabling a master password and setting the "Encrypt entire file"
Most helpful comment
@fela15 No its not fixed by default. You need to make some changes to the configuration of mRemoteNG. Such as enabling a master password and setting the "Encrypt entire file"