by lhunath » Thu Apr 12, 2007 12:14 am
Dear carlpalmer ..
I am no fan of obfuscation. If you wish to suggest obfuscation principles, suggest away, but you will NEVER see obfuscation introduced in jUniUploader.
Security is a SERIOUS thing. Obfuscation is a pathetic attempt at making something look secure.
Let me explain myself.
Any password and username are sent to jUniUploader IN CLEAR TEXT by UniAdmin. You can SEE THE PASSWORD by browsing to this url:
http://my-guild.com/blahblah/uniadmin/interface.php?OPERATION=GETSETTINGSXML
That is your guild's UniAdmin sync url with the query that asks for the settings. Look at its output in your webbrowser, it tells you the password LITERALLY.
If you wish to discuss security, do not come to me, go to Zanix and ask for HTTP authentication and making HTTPS REQUIRED.
Only then, I will considder putting stars on any sort of password in jUniUploader. Currently, it's totally rediculous to try and hide the password. If anything, it will push the WoWRoster devs to become sane and never send passwords on unencrypted streams, accessible by anonymous users.
Last edited by
lhunath on Thu Apr 12, 2007 12:15 am, edited 1 time in total.
"OK, so ten out of ten for style, but minus several million for good thinking, yeah?
"
-- Zaphod Beeblebrox