在我看来,Windows以某种方式加密了这个密码,但由于Windows必须解密它,所以任何人都可以离线访问计算机.
这是真的吗?
是否有可用于恢复这些密码的工具?
Task Scheduler in Windows Vista supports a new credential manager that forms part of the security isolation model. In this model,each set of tasks that runs in a specific security context starts in a separate session. Passwords are now stored in the Credentials Manager (CredMan) service. You can use encryption interfaces with CredMan to prevent malware from stealing stored passwords.
从技术上讲,Credential Manager(较新的Windows版本中的“Credential Locker”)是storing the passwords on the local disk:
Users may choose to save passwords in Windows by using an application or through the Credential Manager Control Panel applet. These credentials are stored on the hard disk drive and protected by using the Data Protection Application Programming Interface (DPAPI). Any program running as that user will be able to access credentials in this store.
(重点补充)
虽然凭据管理器改进了与早期版本的任务计划程序一起使用的已弃用的受保护存储(PStore)服务的加密方法和安全体系结构,但编写的增长仍然有效:无论工具是否公开可用,都可以检索保存的内容为了这个任务.