[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Handling of TortoiseSVN crash report compromises security

From: Stefan Küng <tortoisesvn_at_gmail.com>
Date: Wed, 05 Nov 2008 07:14:58 +0100

Remco Nijhuis wrote:
> Hello,
>
> I came accross a crash report I submitted on TortoiseSVN using the
> automated tool. I didn't know this report was submitted to the mailing
> list org.tigris.tortoisesvn.crashreports. I found it on Google when it
> was included on http://markmail.org/message/oooh2lhlt6tld46l. The report
> includes a zipped .dmp dump file, containing bits and pieces of the
> source code I was working on at the time.
>
> You may imagine that these pieces of source code might include sensitive
> information, e.g. config-files with usernames and passwords to database
> servers used in the project. I regret this being publicly disclosed.
>
> You might want to change procedures to prevent this. As a user, I'd like
> to be warned about data disclosure when I am about to commit a crash
> report. However satisfied I am about your work on TortoiseSVN in
> general, and however much I am committed to help you improve the
> software using these reports, I can't take the risk of spreading
> confidential information. So I am sorry to say that I won't send crash
> reports until this is solved.

I've received a message from the MarkMail guys: they've removed the
index of our crash reports list.

Stefan

-- 
       ___
  oo  // \\      "De Chelonian Mobile"
 (_,\/ \_/ \     TortoiseSVN
   \ \_/_\_/>    The coolest Interface to (Sub)Version Control
   /_/   \_\     http://tortoisesvn.net

Received on 2008-11-05 07:15:19 CET

This is an archived mail posted to the TortoiseSVN Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.