Re: What features shall be handled by SLiMP3 and what features shouldn't?
Anthony Mutiso <[email protected]> Mon, 17 Feb 2003 13:20:36 -0700
| Newsgroups | gmane.music.equipment.slimp3.dev |
|---|---|
| Message-ID | <[email protected]> |
Rather then build authentication/authorization into the product, how about better support for port proxying.... This way one can use squid and apache to support any/all auth/sec scheme. Also when I need to have external access for the service music library, I use an OpenSSH forwarded port tunnel. It works really well. Anthony >>>>> "dean" == dean blackketter <[email protected]> writes: dean> I agree, it just hasn't been implemented yet. On Monday, dean> February 17, 2003, at 09:01 AM, Jason Snell wrote: >> dean blackketter wrote: >> >>> Specifically about your password protection feature, I'd >>> certainly consider it for inclusion in the main server if it >>> didn't make it harder to set up and use, increased the security >>> of the product and wasn't going to be a burden for us to >>> maintain. >> But this is a big deal. Right now you've provided a server that's >> impossible to secure, which means that anyone with a port scanner >> can find it if it's not blocked by a firewall. Even basic HTTP >> authorization as an option would prevent people from browsing your >> library, changing your player settings, and finding your music >> files and downloading them. Providing some level of basic >> authentication, at least as an option, is vital. I'm not saying >> you need to create a users-and-groups interface or an IP range >> restriction or anything, but even my TiVo Web hack >> (tivo.lightn.org) has the ability to do basic authentication. >> >> -jason >> -- >> Jason Snell / Editor, Macworld / jsnell-AANFnQOTzEpWk0Htik3J/[email protected] 415-243-3565 ------------------------ Yahoo! Groups Sponsor ---------------------~--> Get 128 Bit SSL Encryption! http://us.click.yahoo.com/FpY02D/vN2EAA/xGHJAA/rIp0lB/TM ---------------------------------------------------------------------~-> To unsubscribe from this group, send an email to: [email protected] Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/