Problems with FTP transport in Bazaar-NG 0.8

Jan Hudec bulb at ucw.cz
Tue May 16 06:48:23 BST 2006


On Mon, May 15, 2006 at 23:33:03 +0200, Wouter van Heyst wrote:
> On Mon, May 15, 2006 at 03:48:27PM -0500, Bob Tanner wrote:
> > Michal Krenek wrote:
> > 
> > > FTP transport is really important for me and I know also many other people
> > > for which FTP transport is important. I think it would help Bazaar-NG
> > > adoption to have these issues fixed in 0.8.1.
> > 
> > I am thankful that ftp is -not- support because it finally gave me the ammo
> > needed to squash a clear text username/protocol on my network. 
> > 
> > I'm sure others will follow up, but my guess is no one really used ftp
> > anymore because of the security ramifications and the pita of
> > active/passive ftp on firewall configurations
> 
> For some situations though, there is no choice but ftp. We should
> support those cases.

Yes. As long as there are many webhosting services - especially the free
ones - that only allow ftp, it's really very useful.

If you don't use password for such service for anything else (so if
someone gets that password, they don't get anywhere else), don't rely on
it for backup (so if someone gets that password and deletes it, you are
not screwed) and sign your commits (so if someone gets that password
they can't tamper with the repository unnoticed), it's even sufficiently
secure (that is, not very secure but attacker can't do much damage).

-- 
						 Jan 'Bulb' Hudec <bulb at ucw.cz>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : https://lists.ubuntu.com/archives/bazaar/attachments/20060516/20f99f91/attachment.pgp 


More information about the bazaar mailing list