git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] add instructions on how to send patches to the mailing list with Gmail

From
Fredrik Skolmli <fredrik@frsk.net>
Date
Nov 2, 2008, 15:01 UTC
Message-ID
<20081102150100.GF13242@frsk.net>
In-Reply-To
<20081102091006.GA4066@artemis>
On Sun, Nov 02, 2008 at 10:10:06AM +0100, Pierre Habouzit wrote:
Show 8 quoted lines
> > > Warning: It is not secure.
> > 
> > It is true that the certificate is not verified, but since the patches
> > are destined for a public mailing list, this does not represent a
> > large problem.
> 
> What he means is that the password is cleartext ;)
> (I think)

The way I read and understand it, the issues arises if a MITM-attack takes place. If the client doesn't verify the certificate, an attacker can easily get the username and password.

So unless someone creates a separate gmail-account for submitting patches, one should really trust the connection (ie not a public wlan), or verify the certificate before transmitting the password.

-- 
Kind regards,
Fredrik Skolmli
Previous: Pierre Habouzit
Message 5 of 5 in “add instructions on how to send patches to the mailing list with Gmail”
  1. add instructions on how to send patches to the mailing list with GmailTom Preston-Werner, Nov 1, 2008
  2. Santi BéjarNov 1, 2008
  3. Tom Preston-WernerNov 1, 2008
  4. Pierre HabouzitNov 2, 2008
  5. Fredrik SkolmliNov 2, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.