Trac is being migrated to new services! Issues can be found in our new YouTrack instance and WIKI pages can be found on our website.

Changes between Version 9 and Version 10 of SecurityVulnerabilityProcess


Ignore:
Timestamp:
Jan 30, 2010, 8:08:05 PM (14 years ago)
Author:
John Bailey
Comment:

Note that plain-text password storage is not a vulnerability.

Legend:

Unmodified
Added
Removed
Modified
  • SecurityVulnerabilityProcess

    v9 v10  
    1616 * Any proposed embargo dates, release schedules, etc. you or your organization may have established.
    1717
     18Before informing us of security vulnerabilities, please be aware that we will NOT consider our storage of passwords in plain-text a security issue.  We have discussed our position on this at length [wiki:PlainTextPasswords here] and our position on this has not changed.  We will, at a future date, be implementing proper integration with password safes such as gnome-keyring, however that support is not yet ready for general consumption.  Please do not report this particular issue as a security problem.
    1819
    1920= Process for Developers =
All information, including names and email addresses, entered onto this website or sent to mailing lists affiliated with this website will be public. Do not post confidential information, especially passwords!