[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Are http-based password authentications secure?

From: Kalin KOZHUHAROV <kalin_at_thinrope.net>
Date: 2006-04-26 17:41:03 CEST

Nico Kadel-Garcia wrote:
> Matt England wrote:
>> Are authentication passwords given to update a repo that is checked
>> out via "http://" vs "https://" secure, in the sense that their
>> transmission is encrypted?

> Via HTTPS, yes. via HTTP, no. This is why HTTP should frankly never be
> used.

Well, let me give you a few examples where http is useful:
1. A VPN endpoint and SVN/HTTP server on the same machine, no acces except through the (encrypted) VPN
2. A physically secure and isolated (from the Net) LAN
3. Anonymous (RO) public repositories

Just my 3 yen :-)

Kalin.

-- 
|[ ~~~~~~~~~~~~~~~~~~~~~~ ]|
+-> http://ThinRope.net/ <-+
|[ ______________________ ]|
---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@subversion.tigris.org
For additional commands, e-mail: users-help@subversion.tigris.org
Received on Wed Apr 26 17:42:50 2006

This is an archived mail posted to the Subversion Users mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.