Re: plaintext passwords - my 0.02c
From: Saulius Grazulis <grazulis_at_akl.lt>
Date: 2006-07-19 12:45:06 CEST
Hi all,
On Wednesday 19 July 2006 08:08, Stuart Celarier wrote:
> 1. Trust the OS to protect the data...
I can not help to point out one serious flaw in the above argument, a flaw
the data are not always under protection of you OS, even if that OS is
Just think:
a) do we always carefully erase HD before giving the computer to a service
b) are we sure there are no old HDs (with bad sectors, unreliable, but still
c) are we sure all physical backup copies have the same level of authorisation
e) are we sure that all old backup tapes and CDs are properly destroyed and
f) are we sure nobody just took the disk, or one of the mirror raid disks out
Plain passwords on a disk make all the above-mentioned possibilities an easy
If subversion password ever coinsides with a login password (which should
Good encryption of the passwords on the disk greatly diminishes the risk of
It is really great that Subversion team addresses the problem, but I too agree
Regards,
-- Saulius Gražulis Visuomeninė organizacija "Atviras Kodas Lietuvai" P.Vileišio g. 18 LT-10306 Vilnius Lietuva (Lithuania) tel/fax: (+370-5)-210 40 05 mobilus: (+370-684)-49802, (+370-614)-36366
|
This is an archived mail posted to the Subversion Users mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.