From: Larry Jones
Subject: Re: PAM authentication patch - v2
Date: Wed, 16 Apr 2003 10:00:09 -0400 (EDT)

Mark D. Baushke writes:
> Actually, I suspect you are mistaken in your assumptions. It is way too
> easy to mount user volumes or NFS filesystems and access the dot files
> in a user tree if you are on a LAN. Storing passwords or non-password
> protected private ssh keys are always to be discouraged.

Note that CVS creates the ~/.cvspass file with the permissions set so
that only the owner has read permission, so having the file on an NFS-
mounted filesystem is no more dangerous than NFS ever is.

-Larry Jones

