Re: A strong WTF on compiling out plaintext password support by default?!
From: Daniel Shahaf <d.s_at_daniel.shahaf.name>
Date: Fri, 14 Aug 2020 21:44:12 +0000
Daniel Sahlberg wrote on Fri, 14 Aug 2020 23:01 +0200:
Good catch.
> Updated script, I changed to use /usr/bin/env to find zsh
Another good catch. Further improvements: it should set LC_ALL rather
> I even think [SVN_DISABLE_PLAINTEXT_PASSWORD_STORAGE] could
So what would be done with the already-stored password?
- Deleting it would be data loss.
- Keeping it but not using it would needlessly increase the attack
- [There may very well be a third option, but I haven't the time to
Thanks for the bugfixes!
Daniel
|
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.