Ticket UUID: | e5232878345cb71d17cc1631b12dd5903b3d272f | ||
Title: | user passwords are stored in plain text | ||
Status: | Closed | Type: | Feature_Request |
Severity: | Important | Priority: | |
Subsystem: | Resolution: | Works_As_Designed | |
Last Modified: | 2009-09-14 19:19:08 | ||
Version Found In: | 6021279637 | ||
Description & Comments: | |||
user passwords are stored in the fossil repository as plain text instead of a hash.
drh added on 2009-09-12 15:53:03:
We believe that (1) is the better choice since it requires an attacker to be able to see the local database in order to find passwords, and if the attacker can see the local database, then he has already compromised the machine. But with (2), the attack need only passively monitor network communications in order to steal passwords. rwilson added on 2009-09-14 16:40:15: drh added on 2009-09-14 19:19:08: |