[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Re: Credentials held unencrypted in memory during runtime

From: Stefan Küng <tortoisesvn_at_gmail.com>
Date: Mon, 27 Jun 2011 09:00:00 +0200

On Mon, Jun 27, 2011 at 06:48, Ajith Thampi <ajith.thampi_at_ecetera.com.au> wrote:
> Hi Stefan,
>
> Sorry for bringing this up again, but the latest version of TortoiseSVN has not fixed this issue yet.

How can you tell?

> Credentials are still held unencrypted in memory, even though the changelog states it as fixed.

Again: how can you tell?

And besides: read this full thread. And you'll discover that
credentials must be unencrypted *while they're being used*.

> Could you please let me know if this is correct. As highlighted in previous discussions, this fix is important in a financial institution premises.

I will spare you my comment on this for now...

Stefan

-- 
       ___
  oo  // \\      "De Chelonian Mobile"
 (_,\/ \_/ \     TortoiseSVN
   \ \_/_\_/>    The coolest Interface to (Sub)Version Control
   /_/   \_\     http://tortoisesvn.net
------------------------------------------------------
http://tortoisesvn.tigris.org/ds/viewMessage.do?dsForumId=4061&dsMessageId=2778012
To unsubscribe from this discussion, e-mail: [users-unsubscribe_at_tortoisesvn.tigris.org].
Received on 2011-06-27 09:01:06 CEST

This is an archived mail posted to the TortoiseSVN Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.