[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: show differences

From: ESSI - Billie H. Cleek <bcleek_at_essystemsinc.com>
Date: 2006-09-21 21:05:26 CEST

Stefan,

It's not my intention to argue about the security merits, but I do want
to point out that the authentication data is already in RAM by virtue of
two facts: the authentication information exists in the textboxes, and
the authentication information is passed to the server.

In any case, I am able to see my diff just fine, it's just that even
after getting the diff and displaying the TortoiseMerge window there are
repeated authentication attempts. It would seem to me that if I'm doing
a diff and TSVN is able to get that diff and display the TortoiseMerge
window, then what else is it trying to get my authentication information
for?

Stefan Küng wrote:
> ESSI - Billie H. Cleek wrote:
>
> But previous versions also failed many times when trying to do the diff.
> I've decided it's better to let TSVN get some information beforehand and
> use that information for the diff than having it fail too often.
>
>
> But that would mean keeping the authentication data in RAM, and *that*
> would be a security risk (that data could be written to the disk in the
> swap file), or could be read by malware.
>
> And seriously: don't you trust your fellow coworkers in your office that
> little bit? If you don't, then you also must always lock your computer
> when you walk away.
> And besides: if you forget to lock your station and they have access to
> it, then they can do more harm using only your windows credentials than
> they can do with your access to a Subversion repository.
>
> Stefan
>

-- 
Billie H. Cleek
Project Manager
3259 E. Sunshine St
Suite AA
Springfield, Missouri 65804
   Tel: (417) 886-2528
   Fax: (417) 886-2541
bcleek@essystemsinc.com
http://www.essystemsinc.com
PGP: 0xE9734285
Fingerprint = 1CF8 1903 8574 EFAD 0322  1A2E CC02 52B8 E973 4285
---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@tortoisesvn.tigris.org
For additional commands, e-mail: users-help@tortoisesvn.tigris.org
Received on Thu Sep 21 21:07:14 2006

This is an archived mail posted to the TortoiseSVN Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.