Remote Desktop password safety

3

If I access my computer with Remote Desktop from another computer, is my password stored in any way on that computer? Assume that the client computer is "clean" (no virus, malware, keylogger, etc).

Does Remote Desktop do any caching that could potentially expose my information at a later date (after having logged off and closed Remote Desktop)?

user156342

Posted 2013-02-18T20:30:01.207

Reputation:

Your password is not stored. – Ramhound – 2013-02-19T11:52:43.377

Answers

1

I found this answer by splattne.

Apparently Windows caches parts of the screen in %LOCALAPPDATA%\Microsoft\Terminal Server Client\Cache.

To prevent this, disable Bitmap caching or Persistent bitmap caching (depending on your version of Windows).

This could probably be a potential security risk, if someone else was able to open it and see parts of your screen.

user156342

Posted 2013-02-18T20:30:01.207

Reputation:

0

Passwords are encrypted using win credentials API. It's possible to decrypt them if someone intends to. This thread explains in a bit more detail

Mariyan

Posted 2013-02-18T20:30:01.207

Reputation: 1 367

0

As long as you don´t save the password in the .rcp file, one would need physical access to a computer you are currently logged on to crack the password.

Jannis Alexakis

Posted 2013-02-18T20:30:01.207

Reputation: 241