Package: iodine Version: 0.4.0-1 Severity: normal
Because the password is stored in /etc/default/iodine please make sure to install this file with 600 access mode. Also, please modify iodine/iodined to XXX out the password passed to it via the command line. This is not a perfect but certainly substantial security improvement because it makes the password not show up in most "ps xawww" calls. memset(argv[n], 'X', strlen(argv[n])) shold do the job in n is the argument number with the password. Thanks, Lennart -- System Information: Debian Release: lenny/sid APT prefers testing APT policy: (990, 'testing'), (500, 'unstable') Architecture: i386 (i686) Kernel: Linux 2.6.18-4-686 (SMP w/1 CPU core) Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15) Shell: /bin/sh linked to /bin/bash Versions of packages iodine depends on: ii adduser 3.102 Add and remove users and groups ii debconf [debconf-2.0] 1.5.13 Debian configuration management sy ii libc6 2.5-9+b1 GNU C Library: Shared libraries ii makedev 2.3.1-83 creates device files in /dev ii zlib1g 1:1.2.3-13 compression library - runtime iodine recommends no packages. -- debconf information excluded -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]