> First, this is indeed obfuscation. There undoubtedly is a constant key...It's certainly miles beyond what most other sites use
The state of typical security in software projects of the 1990's: sad, sad... Any improvement in 2012: such a piddling little improvement. The trend is clear as is the conclusion: the average dev can't be trusted to do security. It doesn't work!
There isn't much more you can do with the key names really. The issue with them using a static key for encrypting the local password is another thing...
> The issue with them using a static key for encrypting the local password is another thing
Actually, it is the thing that I was referring to. Doing things with the key names is another thing -- wily and probably benefits them a little, but it isn't real security.
The state of typical security in software projects of the 1990's: sad, sad... Any improvement in 2012: such a piddling little improvement. The trend is clear as is the conclusion: the average dev can't be trusted to do security. It doesn't work!