|
|
|
|
|
by blibble
4512 days ago
|
|
correct, which is far from ideal (essentially we're trapped by our CRAM-MD5 support) we've thought long and hard about this too, and don't consider it to be a large threat, as the only two people with access to the box[1] could silently replace the AUTH code and log all the passwords anyway, rendering any secured password store irrelevant. [1]: it's not even known outside the core where the box lives, and it's also essentially completely isolated from the internet at large. |
|
What year is this?