Re: What features shall be handled by SLiMP3 andwhat features shouldn't?
Rob Funk <[email protected]> Mon, 17 Feb 2003 14:42:56 -0500
| Newsgroups | gmane.music.equipment.slimp3.dev |
|---|---|
| Message-ID | <[email protected]> |
Kevin Walsh wrote: >One of the first articles I posted here was about access control lists, >based on a list of "trusted" IP addresses, and I said that I would post >some patches. Of course, I promptly forgot all about it as the machine >that runs my SLIMP3 server is well protected anyway. > >HTTP Basic Authentication sends the username and password in the >clear, so you only get the illusion of security, rather than an actual >secure setup. Pretending to be connecting from one of the IP addresses >in a "trusted" list is a lot trickier, especially if those IP addresses >are all in one of the private address ranges. Ideally both would be implemented, plus the ability to specify which IP address to listen on, so you could limit the server to listening on localhost and not listen on the ethernet interface. That eliminates any possible forgery. -- ==============================| "A microscope locked in on one point Rob Funk <[email protected]> |Never sees what kind of room that it's in" http://www.funknet.net/rfunk | -- Chris Mars, "Stuck in Rewind" ------------------------ Yahoo! Groups Sponsor ---------------------~--> Get 128 Bit SSL Encryption! http://us.click.yahoo.com/FpY02D/vN2EAA/xGHJAA/rIp0lB/TM ---------------------------------------------------------------------~-> To unsubscribe from this group, send an email to: [email protected] Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/