# Security Concern - Found Unencrypted Content in .config File

**URL:** https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045
**Category:** Development
**Created:** [29 May 2020 21:34 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045 "2020-05-29T21:34:31Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![5h3ph3rd](https://avatars.discourse-cdn.com/v4/letter/5/bc8723/32.png) [@5h3ph3rd](https://discourse.joplinapp.org/u/5h3ph3rd)
#### Post date: [29 May 2020 21:34 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045/1 "2020-05-29T21:34:32Z")

</div>

Hi. Posting this because I am concerned I might have uncovered a security flaw with the encrypted feature of the app.

First, I elected to have my content encrypted according to the app’s settings. I thought I was golden until I ran across a hack. I am running the lastest version of Joplin and macOS 10.15 Catalina.

In macOS, if you open the .config file via Terminal, inside is a folder called “resources.” If you open the resources folder you will see a listing of your content but NOT all of it is encrypted as I thought. The text notes part is encrypted but NONE of the PDFs, JPGs, or anything else is encrypted. This is bad because for example what if I took a screenshot of backup security codes. That file would fully viewable.

Did I uncover a security hole? Are the developers aware of this? If so, I urge them to look at it and see if they can also get that content encrypted.

---

<div class="post-metadata">

### Author: ![tessus](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/tessus/32/13_2.png) [@tessus](https://discourse.joplinapp.org/u/tessus)
#### Post date: [29 May 2020 21:35 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045/2 "2020-05-29T21:35:45Z")

</div>

local data is not encrypted

---

<div class="post-metadata">

### Author: ![5h3ph3rd](https://avatars.discourse-cdn.com/v4/letter/5/bc8723/32.png) [@5h3ph3rd](https://discourse.joplinapp.org/u/5h3ph3rd)
#### Post date: [29 May 2020 21:36 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045/3 "2020-05-29T21:36:26Z")

</div>

What about the data I am syncing with Dropbox. Is that encrypted?

---

<div class="post-metadata">

### Author: ![tessus](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/tessus/32/13_2.png) [@tessus](https://discourse.joplinapp.org/u/tessus)
#### Post date: [29 May 2020 21:36 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045/4 "2020-05-29T21:36:34Z")

</div>

yes (if you use E2EE)

---

<div class="post-metadata">

### Author: ![5h3ph3rd](https://avatars.discourse-cdn.com/v4/letter/5/bc8723/32.png) [@5h3ph3rd](https://discourse.joplinapp.org/u/5h3ph3rd)
#### Post date: [29 May 2020 21:37 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045/5 "2020-05-29T21:37:05Z")

</div>

Does this vulnerability concern you or others?

---

<div class="post-metadata">

### Author: ![tessus](https://yyz2.discourse-cdn.com/flex028/user_avatar/discourse.joplinapp.org/tessus/32/13_2.png) [@tessus](https://discourse.joplinapp.org/u/tessus)
#### Post date: [29 May 2020 21:38 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045/6 "2020-05-29T21:38:17Z")

</div>

Me, no. Others, yes.

There have been countless discussions on this forum and on github. I won’t repeat my reasoning. Please search for the topics on this forum.

---

<div class="post-metadata">

### Author: ![5h3ph3rd](https://avatars.discourse-cdn.com/v4/letter/5/bc8723/32.png) [@5h3ph3rd](https://discourse.joplinapp.org/u/5h3ph3rd)
#### Post date: [29 May 2020 21:39 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045/7 "2020-05-29T21:39:37Z")

</div>

Okay. I wlll. I did a quick search and didn’t find anything, thus I posted my question. I’ll try another search. Thanks for the quick answer.

---

<div class="post-metadata">

### Author: ![laurent](https://avatars.discourse-cdn.com/v4/letter/l/ce7236/32.png) [@laurent](https://discourse.joplinapp.org/u/laurent)
#### Post date: [29 May 2020 22:26 UTC](https://discourse.joplinapp.org/t/security-concern-found-unencrypted-content-in-config-file/9045/8 "2020-05-29T22:26:23Z")

</div>

This is addressed in this pull request [https://github.com/laurent22/joplin/pull/3207](https://github.com/laurent22/joplin/pull/3207)
