ghisler(Author) wrote: 2026-06-08, 08:21 UTC
I don't think that this is a security issue users need to be concerned about:
1. An attacker would need physical access to the user's PC
2. The PC has to be running
3. Total Commander must have been opened and a header-encrypted archive must have been opened
4. All the attacker can gain is some file names of a file they may not even be interested in
So even 1 and 2 would be a much bigger problem than this issue.
Point 1, 2 and 3 are not true. TC used data that was encrypted in archives and stored it unencrypted in wincmd.ini.
Point 4 is far from the only possibility.
There doesn't have to be an attacker. It can also concern a family member, a co-worker, a friend, a business partner, an employer, a client, a system administrator, etc.
You say "attackers" may not even be interested in the leaked information. This means you acknowledge that it is possible that they are, but that you have decided that you are willing to take the risk of people having their data leaked and that it may be important.
Names of files and folders can easily be very important. Some examples: "Resignation letter June 8 2026", "Layoff letter Mr. Smith", "Acquisition company X", "New will June 8 2026", "To the ones I left behind".
You say that even 1 and 2 would be a much bigger problem than this issue. That is a deflection away from a security issue you created. The existence of other, worse threats doesn't invalidate real security issues.
BTW, I wasn't claiming this was a critical remote code execution vulnerability or something like that. I asked for transparency via a security notice.
I think that would be appropriate and responsible. Users who rely on header encryption deserve to know their metadata may be exposed, for example via the wincmd.ini file. A notice could inform users of the dangers, what they can do if this matters to them, inform about fixes in the latest version.
white wrote: 2026-06-07, 14:29 UTC
And please mention related changes in TC 11.58 in the help on the page "What's new in this version?".
Can you respond to this please?