You are here

7-Zip: Privacy Leak through %TEMP%

5 posts / 0 new
Last post
PortableMSE
Offline
Last seen: 11 years 10 months ago
Joined: 2012-06-20 00:34
7-Zip: Privacy Leak through %TEMP%

7-Zip Portable still uses the Windows %TEMP% path for its working directory.
This complaint has appeared in this forum several times (eg. in 2008 and again 2010).

This looks like a serious privacy issue for a Portable App.
It runs the risk of leaving plaintext, uncompressed copies of your archived documents on the harddrive of any host machine you happen to plug in to.

I'd like to see an option to let the user set the temp path that 7-Zip Portable uses.
WinZip has had this option since the late '90s.
7-Zip Portable should also include the option to "Use same path as Portable App".
That option would force temp storage to be moved to the removable drive.

I use applications from Portable Apps specifically to maintain a (slightly) elevated level of privacy. Dumping copies of uncompressed files in %TEMP% nullifies this advantage.
It's especially likely to happen in the use-case where the user pulls out a USB drive and walks away without closing everything correctly. But it can also happen if you simply close 7-zip before closing the file viewer.

I know that space may be limited on portable drives, so 7-zip will have to check available space first, estimate working space required, and display a warning/error dialog if space will be tight/insufficient.

Let the temp path default to %TEMP%, to avoid excessive wear on everybody's portable Flash drives. But give the user the option to change the path if they want to.

J Neutron
Offline
Last seen: 1 month 1 week ago
Joined: 2008-06-10 19:26
Config?

Have you tried: Tools > Options > Folders

neutron1132 (at) usa (dot) com

PortableMSE
Offline
Last seen: 11 years 10 months ago
Joined: 2012-06-20 00:34
Config options are ineffective.

Thanks, Jimmy.

I was ready to be embarrassed for a second when I read that post. Like, how could I miss such an obvious option?

So, I went back and tried it again.
And, it doesn't work.

Yes, you can enter a custom path in the "Specified" edit box on the Folders tab of the Options dialog. I unchecked "use for removable drives only", so it should always use the specified path. 7-Zip Portable successfully retains the path setting across application restarts, like it should.

But it will not actually put its temp files in that folder.
They will continue going to %TEMP%, no matter what you set the "Specified" path to.

John T. Haller
John T. Haller's picture
Offline
Last seen: 3 hours 4 min ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
Left Behind

The only possible way to leave it behind would be to kill 7-Zip (or have it crash). Both of which are exceedingly unlikely.

You should be able to change the folder yourself in options. Not sure offhand if this is supported.

An upcoming platform release will let you contain your TEMP directory for all your apps either on the PC or on the drive.

Sometimes, the impossible can become possible, if you're awesome!

PortableMSE
Offline
Last seen: 11 years 10 months ago
Joined: 2012-06-20 00:34
Looking forward to a fix.

Thanks for the info.

See my reply to Jimmy Neutron, above.
It looks like changing the temp path is not supported, as of v9.20.

The "Folders" dialog is there. You can change the "Specified" path. But 7-zip ignores it and continues writing files to %TEMP%.

I look forward to a future release with improved handling of temp data.

Log in or register to post comments