| Re: plaintext passwords - my 0.02c
From: Saulius Grazulis <grazulis_at_akl.lt>
 Date: 2006-07-19 12:45:06 CEST 
Hi all,
 On Wednesday 19 July 2006 08:08, Stuart Celarier wrote:
 > 1. Trust the OS to protect the data...
 I can not help to point out one serious flaw in the above argument, a flaw 
 the data are not always under protection of you OS, even if that OS is 
 Just think:
 a) do we always carefully erase HD before giving the computer to a service 
 b) are we sure there are no old HDs (with bad sectors, unreliable, but still 
 c) are we sure all physical backup copies have the same level of authorisation 
 e) are we sure that all old backup tapes and CDs are properly destroyed and 
 f) are we sure nobody just took the disk, or one of the mirror raid disks out 
 Plain passwords on a disk make all the above-mentioned possibilities an easy 
 If subversion password ever coinsides with a login password (which should 
 Good encryption of the passwords on the disk greatly diminishes the risk of 
 It is really great that Subversion team addresses the problem, but I too agree 
 Regards,
 -- Saulius Gražulis Visuomeninė organizacija "Atviras Kodas Lietuvai" P.Vileišio g. 18 LT-10306 Vilnius Lietuva (Lithuania) tel/fax: (+370-5)-210 40 05 mobilus: (+370-684)-49802, (+370-614)-36366 
 
 | 
This is an archived mail posted to the Subversion Users mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.