mirror of
https://github.com/tahoe-lafs/tahoe-lafs.git
synced 2025-04-10 04:09:58 +00:00
news fragment
This commit is contained in:
parent
aa6360f08e
commit
0b4e6754a3
4
newsfragments/3827.security
Normal file
4
newsfragments/3827.security
Normal file
@ -0,0 +1,4 @@
|
||||
The SFTP server no longer accepts password-based credentials for authentication.
|
||||
Public/private key-based credentials are now the only supported authentication type.
|
||||
This removes plaintext password storage from the SFTP credentials file.
|
||||
It also removes a possible timing side-channel vulnerability which might have allowed attackers to discover an account's plaintext password.
|
Loading…
x
Reference in New Issue
Block a user