|
From: | Christian Grothoff |
Subject: | Re: [GNUnet-developers] Discussion, and Help Wanted: Moving to Gitlab for Git, CI, and Issues |
Date: | Sat, 6 Apr 2019 23:29:04 +0200 |
User-agent: | Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.5.1 |
On 4/6/19 9:47 PM, Florian Dold wrote: > Thanks for taking the time to set this up. So far some things don't > seem right yet: > > There is a massive security problem. Everybody (!!) is able to create > accounts and set their password, *without* being the owner of the > respective email address. As "proof", I've been so friendly to create > an account and sample project "as Christian" (sorry Christian!). > > https://gitlab.gnunet.org/grothoff/gitlab-is-so-awesome-but-insecure I can confirm the hack. Nice job! :-) Go gitlab. Secure by default.
signature.asc
Description: OpenPGP digital signature
[Prev in Thread] | Current Thread | [Next in Thread] |