On Jun 5, 2014, at 12:10 PM, Johan Pelgrim <[email protected]> wrote:
> The other thing is what is the minimal configuration as far as user access is > concerned. I believe all the sync databases have a default GUEST user > configured, but it is disabled? Guest is disabled. Initially we had it enabled, but I decided that it's better to be secure by default. Otherwise someone might not realize that they have to disable guest access, and then end up with a massive security hole. One compromise would be to have a default user account like "admin", but then it needs to have a hardcoded password, and we all know how many attacks there have been on software that ships with hardcoded credentials, because people tend to not remove them. --Jens -- You received this message because you are subscribed to the Google Groups "Couchbase Mobile" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/mobile-couchbase/21085F20-4B4C-4BF9-9DAA-6769B3941737%40couchbase.com. For more options, visit https://groups.google.com/d/optout.
