In reply to <mid:[EMAIL PROTECTED]> :


>> I   noticed   that  protocol  logging  also  logs  the  account  info,
>> username/password.  I  think  the  REAL password should be replaced by
>> asterisks (*)

MM> this is real communication with server, password is stored like it is
MM> sent.

It  shouldn't or it's not safe to log anything at all. I'm pretty sure
the  purpose  of  logging  the  real communication with the server has
nothing to do with the user/password therefor IMHO the password should
be masked (with random size, preferably).

-- 
Best regards,
Goncalo Farias

You can stop reading now, I've finished my message


________________________________________________________
 Current beta is 3.51.9 | 'Using TBBETA' information:
http://www.silverstones.com/thebat/TBUDLInfo.html
IMPORTANT: To register as a Beta tester, use this link first -
http://www.ritlabs.com/en/partners/testers/

Reply via email to