[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

RE: svnserve password store in clear text

From: Ng, Wey Han <weyhan.ng_at_atosorigin.com>
Date: 2004-06-04 05:49:44 CEST

> -----Original Message-----
> From: Benjamin Pflugmann [mailto:benjamin-svn-dev@pflugmann.de]
> Sent: Friday, June 04, 2004 2:59 AM
>
> > > Although theoretically I might be able to use a brute-force or
> > > dictionary attack against their password, I'm not going to.
> > > (Even reversible encryption/obfuscation on the password would meet
> > > this goal).
> >
> > Yeah. Same here. BTW, how did you manage to read my mind so
> completely? :)
>
> That means, simply base64 encoding would do for you?

YES! But I would also prefer the solution to be just a small change to the
server side on the existing authentication system so that this change do not
break the clients. Clients like TortoiseSVN is self contain and changing the
library means building TortoiseSVN to have the change in effect.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Received on Fri Jun 4 05:57:40 2004

This is an archived mail posted to the Subversion Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.