Re: Security of `dupload' and `pwgen'?

On Sep 18, Karl M. Hegbloom wrote
:  Q1: Does `dupload' send the password across the Internet in the clear?
:      Should I be using `ssh' instead, for that reason?[1]

Yes, as every other ftp or telnet session does.  IFF you use ftp as the
upload method.

You can use scp.

:  Q2: If I generate a password with `pwgen', couldn't someone run it in a 
:      loop for a while, and collect the passwords it makes to use in
:      guessing the maintainer's passwords?


: Footnotes: 
: [1]  If I use `scp', how do I make the announcement to devel-changes?

Here is a part of my /etc/dupload.conf.  IMHO dupload installs a very close
dupload.conf, or at least a similar in /usr/doc/dupload/examples.

# upload to master, using ssh/scp

$cfg{master} = {
	fqdn => "",
	method => "scp",
	login => getlogin() || $ENV{USER} || $ENV{LOGNAME},
	incoming => "/home/Debian/ftp/private/project/Incoming/",
	mailto => "debian-changes\", # stable, contrib, non-free
	mailtx => "debian-devel-changes\",	# unstable, exper.
	visibleuser => getlogin() || $ENV{USER} || $ENV{LOGNAME},
	visiblename => "",
	fullname => "",

... I admit, the manpage duplod(5) istn't _very_ clear about the method
``scp'' ... but the has nothing to do with the way the announcment is
done.  The announcements are always done via sendmail.

