Re: (fwd) Re: [PHP-DEV] CVS Account Request
| From: | Sascha Schumann | Date: | Fri, 17 Nov 2000 13:13:54 +0000 |
| Subject: | Re: (fwd) Re: [PHP-DEV] CVS Account Request | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-38409@lists.php.net to get a copy of this message | ||
On Fri, 17 Nov 2000, Teodor Cimpoesu wrote:
>
> Hi all,
>
> sent only to Rasmus by accident. An important issue I though...
>
> > As far as a terrorist cvs committer goes. I think you are being overly
> > paranoid. And I would challenge the statement that an unknown can sneak a
> > harmful commit into PHP that is not caught by anybody.
>
> I would go further and say that a black hat doesn't even need a cvs account.
> it's enough to watch the cvs commits to see who what acoounts has, then say
> I see `sas' and gee, I have access to a machine in the same network as the
> one apparently originating the commits.
>
> Rember pserver is the *weakest* security choice, so I can sniff it's scrambled
> cvs password. Tada! Now I can do commits as `sas'.
>
> So if you really want top security, setup ssh with 2048 public keys, request
> a blood sample before grating CVS accounts, so forth :)
Yes, there is a certain risk associated with pserver, but I
don't think it is high enough to raise the barrier for
developers even more. If you are afraid of someone sniffing
your passwords on the client side, consider a switched
network or just getting a dial-up account somewhere.
Don't let us begin another paranoia round.. ;-)
- Sascha