RE: plaintext passwords - my 0.02c
From: Stuart Celarier <SCelarier_at_corillian.com>
Date: 2006-07-19 07:08:58 CEST
I'm with you, Paul. Subversion *is* a hard sell to folks with 'Security'
The FAQ entry on plaintext passwords is probably the single biggest deal
http://subversion.tigris.org/faq.html#plaintext-passwords
I'm focusing solely on what the FAQ says, not whether it is correct or
1. Trust the OS to protect the data. Sure, until the OS is compromised,
2. If you don't want passwords stored in plaintext, you have the option
3. Aw, heck, all my friends are doing it, worse actually, so what's the
3a. And no one cares about this problem enough to do anything about it.
Four reasons to say no; no reasons to say yes. Case closed.
I suggest that rewriting this FAQ item to be more security savvy could
Stuart Celarier | Corillian Corporation
---------------------------------------------------------------------
|
This is an archived mail posted to the Subversion Users mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.