﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc	mlocked
9555	Insecure password handling by mythfilldatabase	Marc Randolph <mrand@…>	beirdo	"
1. It uses http (rather than https) in the wget command, so schedules direct password is being transmitted in the clear across the internet

2. The schedules direct password is placed on the command line of the wget command, which potentially allows any user that shares that system can see the password in the clear

If these can't be fixed, perhaps a warning should be displayed on the schedules direct setup screen that these behaviors will be occuring so that the user can be forewarned.

Forwarding upstream from: https://bugs.launchpad.net/ubuntu/+source/mythtv/+bug/672895
"	Bug Report	closed	major	0.25	MythTV - Mythfilldatabase	0.24-fixes	medium	Fixed			0
