Re: PAM authentication patch - v2

From: Brian Murphy
Subject: Re: PAM authentication patch - v2
Date: Wed, 16 Apr 2003 09:31:30 +0200
Mark D. Baushke wrote:

I doubt I can convince you of how evil it is to send passwords in the
clear for your :pserver: connections to cvs. I just shudder to think of
folks seeing that cvs support PAM and thinking for some reason that it
is not leaking their passwords in a large number of ways.

PAM also works with telnet. I don't think anyone thinks a PAM enabled login
via telnet is any more secure than an ordinary passwd based login.


