Hi,

I am forwarding Debian bug 106391.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=106361&repeatmerged=yes

The bug still applies. 

---- 


this is from the "advanced usage" section of examples (info docs):

>   * If you want to encode your own username and password to HTTP or
>     FTP, use the appropriate URL syntax (*note URL Format::).
>
>          wget ftp://hniksic:[EMAIL PROTECTED]/.emacs

this would let other users on the system to see your password
using "ps". it should have a big disclaimer.

there are also other places in the documentation that talk
about putting passwords in urls, but do not say anything about
the potential security implications (search for "password").

----

Please keep [EMAIL PROTECTED] CC'ed.

-- 
Guillaume Morin <[EMAIL PROTECTED]>

                       Alcôve - L'informatique est libre
                           http://www.alcove.com/fr/

Reply via email to