Re: [Savannah-hackers-public] [Repo-criteria-discuss] Savannah and HTTPS

2016-10-10 Thread Mike Gerwitz
ews.ycombinator.com/item?id=10592775 [1]: https://blog.wikimedia.org/2015/06/12/securing-wikimedia-sites-with-https/ -- Mike Gerwitz Free Software Hacker+Activist | GNU Maintainer & Volunteer GPG: 2217 5B02 E626 BC98 D7C0 C2E5 F22B B815 8EE3 0EAB https://mikegerwitz.com signature.asc Description: PGP signature

Re: [Savannah-hackers-public] [Repo-criteria-discuss] Savannah and HTTPS

2016-10-10 Thread Mike Gerwitz
rs---who handles the systems that monitor logs for threats---notified me that my password was plaintext in the logs. Fortunately, he is a good guy. And fortunately, my Nature account wasn't sensitive, and used a password unique to that website; if my password were shared, accounts on other websites would e

Re: [Savannah-hackers-public] [Repo-criteria-discuss] Savannah and HTTPS

2016-10-09 Thread Mike Gerwitz
intext, before then being redirected (and reposted) over a secure connection. -- Mike Gerwitz Free Software Hacker+Activist | GNU Maintainer & Volunteer GPG: 2217 5B02 E626 BC98 D7C0 C2E5 F22B B815 8EE3 0EAB https://mikegerwitz.com signature.asc Description: PGP signature

Re: [Savannah-hackers-public] [Repo-criteria-discuss] Savannah and HTTPS

2016-10-07 Thread Mike Gerwitz
erating savannah read this, but I'd recommend > these changes: > * Remove the nonsensical login option and make security the default. > * Redirect all http queries to https. > * Set an HSTS header to avoid accidental http access. > * Create an anonymous git checkout option over HTTPS. >

Re: [Savannah-hackers-public] Sender root@localhost

2016-07-22 Thread Mike Gerwitz
p://www.gnu.org/copyleft/gpl.html. ___ Message sent via/by Savannah http://savannah.nongnu.org/ --- End Message --- signature.asc Description: PGP signature -- Mike Gerwitz Free Software Hacker+Activist | GNU Maintainer & Volunteer https://mikegerwitz.com | GPG Key ID: 0x8EE30EAB

Re: [Savannah-hackers-public] Sender root@localhost

2016-07-21 Thread Mike Gerwitz
ving access to that box. Thanks for the reply! It's not a huge deal given other priorities that likely exist, as long as it's not causing other problems. -- Mike Gerwitz Free Software Hacker+Activist | GNU Maintainer & Volunteer https://mikegerwitz.com | GPG Key ID: 0x8EE30EAB signature.asc Description: PGP signature

[Savannah-hackers-public] Sender root@localhost (was: Project Approved)

2016-07-21 Thread Mike Gerwitz
Hopefully this is the correct mailing list for this: The sender for the approval e-mail for Savannah is 'root@localhost'. On Wed, Jul 20, 2016 at 17:38:17 +, root@localhost wrote: > > Your project registration for Savannah has been approved. -- Mike Gerwitz Free Software