Re: encryption of password

savita <[email protected]>
Newsgroups gmane.comp.jakarta.slide.user
Message-ID <[email protected]>

Tyr to store password in   xmlns:S="http://jakarta.apache.org/slide/"
namespace instead of DAV:
  
Changing the namespace did not work. Meanwhile, I have the folowing reply
from Joe Feise of DAV Explorer.
Hello Sativa,
It obviously is a bug in Slide to transmit the password in the clear. I
actually consider this a major security issue in Slide.
I suggest filing a bug report with the Slide developers.
In the meantime, I see if DAV Explorer can block out the password. But that
of course would only be an "security through obscurity" measure. If the user
logs all data that goes over the wire, the user would still be able to see
the password.
Regards,
-Joe

I am not sure if this qualifies as a bug, but it does cause security issues. 




-- 
View this message in context: http://www.nabble.com/encryption-of-password-tf2219319.html#a6282226
Sent from the Jakarta Slide - User forum at Nabble.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.