#1089: authentication
--------------------------+-------------------------------------------------
 Reporter:  martinlindhe  |       Owner:  damoxc   
     Type:  bug           |      Status:  accepted 
 Priority:  major         |   Milestone:  1.3.0    
Component:  webui         |     Version:  1.2.0_rc4
 Keywords:                |  
--------------------------+-------------------------------------------------

Comment(by martinlindhe):

 Yes of course i changed the password and port before even coming here.

 The reason for opening the ticket is because i am confused by the security
 model.
 Then i got confused by the server-client model aswell.

 if a web-ui is installed on the default port and the user have tested it
 out (connecting to localhost deluged daemon) and the web ui stores the
 daemon connection as a bookmark, then all someone needs is a password (no
 username) to connect to the added server(s) through the web-ui later.

 but since both the password and default port have known defaults, it
 sounds scary to me.

 please notice 1.2 will be pushed into popular end-user distros like ubuntu
 soon and many non-technical people will try this out since it's available.

-- 
Ticket URL: <http://dev.deluge-torrent.org/ticket/1089#comment:6>
Deluge <http://deluge-torrent.org/>
Deluge project

--

You received this message because you are subscribed to the Google Groups 
"Deluge Dev" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/deluge-dev?hl=en.


Reply via email to