Re: (fwd) Re: [PHP-DEV] CVS Account Request

From: Date: Fri, 17 Nov 2000 13:13:54 +0000
Subject: Re: (fwd) Re: [PHP-DEV] CVS Account Request
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-38409@lists.php.net to get a copy of this message
On Fri, 17 Nov 2000, Teodor Cimpoesu wrote: > > Hi all, > > sent only to Rasmus by accident. An important issue I though... > > > As far as a terrorist cvs committer goes. I think you are being overly > > paranoid. And I would challenge the statement that an unknown can sneak a > > harmful commit into PHP that is not caught by anybody. > > I would go further and say that a black hat doesn't even need a cvs account. > it's enough to watch the cvs commits to see who what acoounts has, then say > I see `sas' and gee, I have access to a machine in the same network as the > one apparently originating the commits. > > Rember pserver is the *weakest* security choice, so I can sniff it's scrambled > cvs password. Tada! Now I can do commits as `sas'. > > So if you really want top security, setup ssh with 2048 public keys, request > a blood sample before grating CVS accounts, so forth :) Yes, there is a certain risk associated with pserver, but I don't think it is high enough to raise the barrier for developers even more. If you are afraid of someone sniffing your passwords on the client side, consider a switched network or just getting a dial-up account somewhere. Don't let us begin another paranoia round.. ;-) - Sascha

« previous php.dev (#38409) next »