[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: cleartext passwords

From: Karl Fogel <kfogel_at_newton.ch.collab.net>
Date: 2002-11-10 23:52:08 CET

Nuutti Kotivuori <naked@iki.fi> writes:
> I don't see a reason why we couldn't base64 the password if wanted,
> but I'd like to see a case where one could stuble on it by mistake
> first.

We did something similar in CVS (for the pserver access method).
FWIW, I think it wasn't worth it. It may obscure the password from a
few accidental exposures, but it also gets in people's way when they
needed to see the cleartext that they knew was there, and of course it
provides no real added security.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Received on Mon Nov 11 00:25:48 2002

This is an archived mail posted to the Subversion Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.