RE: Credentials held unencrypted in memory during runtime
From: Wayne Johnson <wayne_at_zk.com>
Date: Wed, 13 Apr 2011 09:45:54 -0700
> I'd be curious if Stefan's views of secure coding best practices is
Really!? I am flabbergasted. Stefan politely tells you he has better things to do with *his* free time and you guys just keep after him. He even ask for suggestions on how to handle this and instead of receiving any useful feedback he just gets crap...
Every software project (everything in life for that matter) boils down to a list of trade-offs. One person (or company) can't do everything so you sit down and decide what the most important things are. To me, Stefan, and a bunch of other people using TSVN, this is not the most important thing at this point. If it's really that important to you, checkout the source code, fix it, and provide a patch. If you don't have the expertise to do hire one of the several security experts who frequent this list.
I would like to say more but I think I just bit my tongue off...
Wayne
------------------------------------------------------
To unsubscribe from this discussion, e-mail: [users-unsubscribe_at_tortoisesvn.tigris.org].
|
This is an archived mail posted to the TortoiseSVN Users mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.