On Jun 5, 2014, at 12:10 PM, Johan Pelgrim <[email protected]> wrote:

> The other thing is what is the minimal configuration as far as user access is 
> concerned. I believe all the sync databases have a default GUEST user 
> configured, but it is disabled?

Guest is disabled. Initially we had it enabled, but I decided that it's better 
to be secure by default. Otherwise someone might not realize that they have to 
disable guest access, and then end up with a massive security hole. One 
compromise would be to have a default user account like "admin", but then it 
needs to have a hardcoded password, and we all know how many attacks there have 
been on software that ships with hardcoded credentials, because people tend to 
not remove them.

--Jens

-- 
You received this message because you are subscribed to the Google Groups 
"Couchbase Mobile" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/mobile-couchbase/21085F20-4B4C-4BF9-9DAA-6769B3941737%40couchbase.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to