[Tracker-discuss] [issue518] Plaintext connections when logging in

2013-07-09 Thread anatoly techtonik

anatoly techtonik added the comment:

https does help those with security knowledge to login safely.

--
nosy: +techtonik

___
PSF Meta Tracker metatrac...@psf.upfronthosting.co.za
http://psf.upfronthosting.co.za/roundup/meta/issue518
___
___
Tracker-discuss mailing list
Tracker-discuss@python.org
http://mail.python.org/mailman/listinfo/tracker-discuss


[Tracker-discuss] [issue518] Plaintext connections when logging in

2013-06-28 Thread R David Murray

R David Murray added the comment:

As Martin (I think) has said, just how damaging would compromising this 
password be?  Tracker changes are all reversible.

On the other hand I'm in favor of using https in general.  This was discussed 
on the infrastructure list, and the issue is that bugs is hosted on different 
infrastructure.  bugs is probably the last service that will be addressed.  If 
this concerns you enough you could check back in the infrastructure mailing 
list archives for that discussion, and figure out whether there is a next step 
we could take in the meantime (I think putting a copy of the *.python.org cert 
or getting a bugs.python.org cert was discussed, but I don't remember for 
sure).  I'm willing to help with the server config part of it, but I'm not 
worried enough about it to drive the process myself :)

--
nosy: +r.david.murray
status: unread - chatting

___
PSF Meta Tracker metatrac...@psf.upfronthosting.co.za
http://psf.upfronthosting.co.za/roundup/meta/issue518
___
___
Tracker-discuss mailing list
Tracker-discuss@python.org
http://mail.python.org/mailman/listinfo/tracker-discuss


[Tracker-discuss] [issue518] Plaintext connections when logging in

2013-06-28 Thread R David Murray

R David Murray added the comment:

Well, yes, I know that is common.  Unfortunately, https doesn't solve that lack 
of security knowledge, since if one account gets cracked because of insecure 
servers, the rest of their accounts are also compromised.

___
PSF Meta Tracker metatrac...@psf.upfronthosting.co.za
http://psf.upfronthosting.co.za/roundup/meta/issue518
___
___
Tracker-discuss mailing list
Tracker-discuss@python.org
http://mail.python.org/mailman/listinfo/tracker-discuss