In reply to <mid:[EMAIL PROTECTED]> :


ASK> Hello Goncalo Farias & everyone else,

ASK> on 23-Jul-2005 at 13:25 you (Goncalo Farias) wrote:

>> Do you believe there is REAL need for the plain text password? Most
>> people  is,  possibly,  unaware the PLAIN TEXT password is store in
>> that log.

ASK> If  you're  not  using  a secure method of authentication, the PW
ASK> will  be  sent as plaintext to the server. Crossing it out in the
ASK> log  is just a false sense of security, and at the wrong point as
ASK> well.

I do agree with partially... I prefer to have a weak point rather than
two.  Besides,  having  it  save in the log exposes it to whomever has
access  to  the  PC where the log is saved, not just the John Doe that
sniffs the net!.


-- 
Best regards,
Goncalo Farias

"A man's a man for a' that!" Burns


________________________________________________________
 Current beta is 3.51.9 | 'Using TBBETA' information:
http://www.silverstones.com/thebat/TBUDLInfo.html
IMPORTANT: To register as a Beta tester, use this link first -
http://www.ritlabs.com/en/partners/testers/

Reply via email to