Re: [fossil-users] Fossil security question from a newbie

2015-03-18 Thread Stephan Beal
On Mar 18, 2015 5:01 AM, Vikrant Chaudhary vikr...@webstream.io wrote: No, the authentication/authorisation is only to protect if the repository is accessed over a protocol (http, command line etc.), if Minor correction: in cli mode the user is effectively an admin. No rights are checked in

Re: [fossil-users] Fossil security question from a newbie

2015-03-17 Thread sky5walk
The repo is an open SQLite db. You can browse it easily with any 3rd party ​SQLite viewer/editor or your own code. The passwords are hashed but available. As are the user settings. So, someone could edit the user guest cap to 'as' and do whatever. Better to encrypt the repo when in transit. On

Re: [fossil-users] Fossil security question from a newbie

2015-03-17 Thread Vikrant Chaudhary
No, the authentication/authorisation is only to protect if the repository is accessed over a protocol (http, command line etc.), if someone has direct access to the file, they have access to _all_ of the repository data. To protect any file on a USB drive against theft or loss, you'll need to

[fossil-users] Fossil security question from a newbie

2015-03-17 Thread Byung-Jae Kwak
Hello, Suppose I have .fossil file on a thumb drive and I lost it. If all the privileges of all the accounts in the repository have been disabled except for the admin account, and the admin account is protected with a fairly strong password, can I assume the content in the repository is