Comment #8 on issue 1552 by chipx86: Need option to expire cookies
We don't take security lightly, but you must understand that every
we've seen so far has a Review Board server behind a corporate
firewall/VPN, and so
we optimize for that.
I have a strong feeling that if we added a checkbox for this setting, it
would not be
used by more than one or two installs. Those installs are already in
because, while security is important, we can't guarantee that Review Board,
Djblets, Pygments, Python, paramiko, mod_python, Subversion, Git, Apache,
other thing in our stack is secure and free of bugs that would allow a user
control over a system.
If your setup is such that a stolen laptop or PDA can be used to access
Board server, then that's a security problem with your overall install, not
software. Just as you would hopefully not make your entire repository
the outside world without a VPN, you shouldn't make your Review Board server
accessible. And if you are accessing even your internal server with a
computer/device, then it's your responsibility to secure it and make sure
it's stolen, they can't get access to anything. Many companies have a
using encrypted filesystems for this very reason.
Sorry if it seems like security isn't a priority to us. It is. This is not
for it though, at least not one that will do anything other than give the
solving the problem.
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
You received this message because you are subscribed to the Google Groups
To post to this group, send email to reviewboard-iss...@googlegroups.com.
To unsubscribe from this group, send email to
For more options, visit this group at