From: Krzysztof Halasa Date: Sun, 20 Nov 2005 20:46:59 GMT Subject: Re: [PATCH] Support username and password inside URL Message-ID: In-Reply-To: <7vwtj3xe72.fsf@assigned-by-dhcp.cox.net> Junio C Hamano writes: > It is handy to have weak "authentication" in some situations. I > am not ashamed to admit that I've used security-by-obscurity > myself, when I sent an email to a friend, saying: > > Hi, I have some pictures I took during our last trip > together, but due to their size I am not attaching them > to this e-mail. Please pick them up at: > > http://members.cox.net/junkio/r0ZIEF/5S54m/ If the above is security by obscurity then any password scheme is, too. After all you're obscuring the password, right? Well, private key and its password can be obscure as well. :-) A common definition says that security by obscurity is using a hidden algorithm and not a shared or private secret. -- Krzysztof Halasa