On 11 March 2011 14:15, Vitaly Liaschuk <[email protected]> wrote:

> Thanks for your answer.
> We going to search other way to store our passwords.


What we do is have a file readable only by root stored in a particular
place, known to the sysadmins, our boss and our boss's boss (the
latter two not using it, but knowing that this is the "everyone hit by
a bus" document). The file in question is referred to on the wiki as
"password in the usual place." A suitable combination of actual
security and a bit of obscurity ;-) The threat model is not a
malicious intruder, but a well-meaning co-worker - the latter is ten
times as damaging.


- d.

_______________________________________________
MediaWiki-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-l

Reply via email to