List Info

Thread: Re: encrypted pagestore?




Re: encrypted pagestore?
country flaguser name
United States
2008-01-06 13:06:46
--- christian.ridderstromgmail.com wrote:
> I think there's also a threat situation where
> non-root users on the server 
> can read files in wiki.d/, e.g. 'apache'.  In this
> case, having the files 
> encrypted could help, although key management is
> still a problem.

Sure, but I would just classify that as the same
threat (or maybe less of) as #2:

2) who can sniff your ftp password and therefor even
access the files once they are on the server (sounds
like yes also?)

A local use might be even less of a threat than
someone who has your ftp password.  The local user can
likely only see files that you give world readable
permissions to, the ftp user can see everything you
can see.

-Martin



     
____________________________________________________________
________________________
Be a better friend, newshound, and 
know-it-all with Yahoo! Mobile.  Try it now.  http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9
tAcJ 


_______________________________________________
pmwiki-devel mailing list
pmwiki-develpmichaud.com
http://www.pmichaud.com/mailman/listinfo/pmwiki-devel

Re: encrypted pagestore?
country flaguser name
Sweden
2008-01-06 15:28:53
On Sun, 6 Jan 2008, Martin Fick wrote:

> --- christian.ridderstromgmail.com wrote:
>> I think there's also a threat situation where
>> non-root users on the server
>> can read files in wiki.d/, e.g. 'apache'.  In this
>> case, having the files
>> encrypted could help, although key management is
>> still a problem.
>
> Sure, but I would just classify that as the same
> threat (or maybe less of) as #2:
>
> 2) who can sniff your ftp password and therefor even
> access the files once they are on the server (sounds
> like yes also?)
>
> A local use might be even less of a threat than someone
who has your ftp 
> password.  The local user can likely only see files
that you give world 
> readable permissions to, the ftp user can see
everything you can see.

I see. In my case, I don't use ftp, but there are other
users on the 
machine and the wiki.d/-pages are generally world readable.
Not sure why 
though... maybe it's the default?  Patrick?

/Christian

-- 
Christian Ridderström, +46-8-768 39 44               http://www.md.kth.se/~chr
_______________________________________________
pmwiki-devel mailing list
pmwiki-develpmichaud.com
http://www.pmichaud.com/mailman/listinfo/pmwiki-devel

[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )