[josm-dev] shocking - unsecure password sending!

GeoJ geoj at quantentunnel.de
Thu Sep 24 16:25:36 BST 2009


Frederik Ramm schrieb:
> No, because the API does not support https (supporting https would 
> probably come at a considerable speed penalty especially if nut using 
> changeset uploads).

May be the HTTP digest authentication would be an alternative (or a
similar approach)? It uses a clear-text challenge-response protocol that
does not require SSL but protects the password.

GeoJ





More information about the josm-dev mailing list