James A Baker kirjoittaa:On Wednesday, Oct 1, 2003, at 00:59 US/Central, matti wrote:[...] If these files are backward browsable with visible history is insingificant. [...]No. The point is that this *IS* significant. -- Maybe not to you necessarily, but it would be to other people who might be accessing their account from someone else's computer. -jab
Rubbish The *DEMO* is open. Password is public. Where is the risk?
They're saying that they're concerned the riwos code does the same with all accounts, not just the demo you made available.
Personally, I haven't investigated the issue, because I don't actually plan on installing riwos. -- SqWebMail is enough for me to configure by itself... I don't much want to install another whole product that's based on sqwebmail, just to test that one out too. =)
If the main riwos code doesn't expose the URL paths to history lists, then that's great. But the other guys were saying they seemed to think (apparently based on their experience with the demo) that it merely hid the URL's from the user's window... and not from the history list like sqwebmail does.
As for me... I don't know. I haven't even tried to determine whether it does or not. :-) I was just saying their concern is valid -- if what they think happens, does happen.
-jab
