Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security concerns #57

Open
ghost opened this issue Jun 1, 2016 · 3 comments
Open

Security concerns #57

ghost opened this issue Jun 1, 2016 · 3 comments

Comments

@ghost
Copy link

ghost commented Jun 1, 2016

Hello,

I've got serious concerns about the security of this module. If someone puts their credentials in the UI, they're sending them in the clear, and if a large company did this, they would be exposing the company, and Akamai, to serious issues. Additionally, anyone who can see the database (are the credentials stored in the clear like Wordpress?) can access the credentials.

It would be much better to instruct people to send the credentials to the system via sftp. It may be more of an issue, but it would be better than what's being done now. It's critically important that these credentials be protected, and without HTTPS and database protection, the users should access this file as an sftp target.

Our security folks will likely have serious issues with this as well.

Kirsten Hunter
API Evangelist, Akamai

@arknoll
Copy link

arknoll commented Jun 1, 2016

@synedra I cross-posted your issue over on drupal.org https://www.drupal.org/node/2738995

@cam8001
Copy link
Contributor

cam8001 commented Jun 2, 2016

Hi Synedra,

Thanks for your report. I am reviewing your concerns and will respond shortly. It's probably best to keep discussion on Drupal.org - would you mind registering for an account there? The link arknoll provided above is my preffered place to respond.

@cam8001
Copy link
Contributor

cam8001 commented Jun 2, 2016

Replied on Drupal.org thread: https://www.drupal.org/node/2738995#comment-11256377

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants