[josm-dev] shocking - unsecure password sending!

Valent Turkovic valent.turkovic at gmail.com
Thu Sep 24 12:12:23 BST 2009


Hi,
I was amazed when my OSM username and password appeared on "Wall of 
Sheep" during the conference at which I was presenting OpenStreetMap 
project!

I was using JOSM only to download some data, and I wasn't aware that JOSM 
sends login data even when it is only downloading data and not sending.

The real shock was that my username and password were being send via 
clear text.

Can JOSM use https or some other secure way of logging into OSM?

Cheers from Croatia,
Valent.



-- 
pratite me na twitteru - www.twitter.com/valentt
http://kernelreloaded.blog385.com/
linux, blog, anime, spirituality, windsurf, wireless
registered as user #367004 with the Linux Counter, http://counter.li.org.
ICQ: 2125241, Skype: valent.turkovic





More information about the josm-dev mailing list