Re: [PATCH] Support username and password inside URL
- From
- Krzysztof Halasa <khc@pm.waw.pl>
- Date
- Nov 20, 2005, 20:46 UTC
- Message-ID
- <m3br0fujwc.fsf@defiant.localdomain>
- In-Reply-To
- <7vwtj3xe72.fsf@assigned-by-dhcp.cox.net>
Junio C Hamano <junkio@cox.net> writes:
Show 9 quoted lines
> It is handy to have weak "authentication" in some situations. I > am not ashamed to admit that I've used security-by-obscurity > myself, when I sent an email to a friend, saying: > > Hi, I have some pictures I took during our last trip > together, but due to their size I am not attaching them > to this e-mail. Please pick them up at: > > http://members.cox.net/junkio/r0ZIEF/5S54m/
If the above is security by obscurity then any password scheme is, too. After all you're obscuring the password, right? Well, private key and its password can be obscure as well. :-)
A common definition says that security by obscurity is using a hidden algorithm and not a shared or private secret.
-- Krzysztof Halasa