Thread (1 message) 1 message, 1 author, 2016-06-15

Re: [PATCH] Support username and password inside URL

From: Krzysztof Halasa <khc@pm.waw.pl>
Date: 2016-06-15 22:42:12

Junio C Hamano [off-list ref] writes:
It is handy to have weak "authentication" in some situations.  I
am not ashamed to admit that I've used security-by-obscurity
myself, when I sent an email to a friend, saying:

        Hi, I have some pictures I took during our last trip
        together, but due to their size I am not attaching them
        to this e-mail.  Please pick them up at:

	        http://members.cox.net/junkio/r0ZIEF/5S54m/
If the above is security by obscurity then any password scheme is, too.
After all you're obscuring the password, right?
Well, private key and its password can be obscure as well. :-)


A common definition says that security by obscurity is using a hidden
algorithm and not a shared or private secret.
-- 
Krzysztof Halasa
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help