[josm-dev] shocking - unsecure password sending!

Dirk Stöcker openstreetmap at dstoecker.de
Fri Oct 2 20:20:15 BST 2009


On Thu, 24 Sep 2009, Valent Turkovic wrote:

> I was amazed when my OSM username and password appeared on "Wall of
> Sheep" during the conference at which I was presenting OpenStreetMap
> project!
>
> I was using JOSM only to download some data, and I wasn't aware that JOSM
> sends login data even when it is only downloading data and not sending.

In rev. 2222 the capabilities request no longer sends username/password. 
This means again only uploads require authentication.

Ciao
-- 
http://www.dstoecker.eu/ (PGP key available)





More information about the josm-dev mailing list