Github user kanzhang commented on the pull request:

    https://github.com/apache/spark/pull/6676#issuecomment-110544598
  
    > Ignoring that if you really want you can find the secret by looking at 
the memory of another process, all that the secret prevents is someone 
connecting back to the driver and pretending to be an executor. Given all of 
the above, is that really giving any extra security to the app?
    
    Oh, I missed your point in my last reply.  Yes, I do think there is some 
extra security to be gained by having a per-app secret key for securing per-app 
communications, assuming there is not a trivial way to compromise the per-app 
key.


---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at [email protected] or file a JIRA ticket
with INFRA.
---

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to