使用Google Gears创建离线应用的时候,会在本地生成db文件,但是这些db文件确是无法加密码的,这就造成一个安全问题:假如你的机子变成肉鸡,你的机密数据是否就完全暴露了呢? 我在gears users用户群里发了这个问题,Google的技术人员给我回复:
   Michael Nordman wrote: 
    > if your computer be hacked by someone, your data will be revealed.

    This is true. The local data managed by Gears is no more secure than
    any other unencrypted data stored in your OS user profile. There is
    one flavor of .db file that we have discussed encrypting (optionally),
    .db files created on behalf of Gears.Database objects. However, there
    are absolutely no plans to do that.

             On Mar 4, 4:04 pm, 浩翔 wrote:
                   Hi all,

                  Whether I can add password for gears database ? How to do it ?
                  Because gears database generated geolocation.db,localserver.db and
                  permissions.db if you use windows,
                  if your computer be hacked by someone, your data will be revealed.
                 Thanks !

             Alex

看来google自己也认识到这个问题了,希望gears早日改进,能增加对db加密的功能! 

另附一条新闻: 安全研究人员MichaelSutton周三(2月18)在黑帽大会上展示如何利用网站上的跨站脚本***(cross-siteting,XSS)漏洞存取被***者计算机中所储存的GoogleGears离线资料库。