X-Git-Url: https://git.rkrishnan.org/?p=tahoe-lafs%2Ftahoe-lafs.git;a=blobdiff_plain;f=NEWS.rst;h=5bc827bb70cde3f2b461cb840507948ee2574919;hp=19aacfbf1d0844039237d604f6a85e64a0795a46;hb=7ae630559fc3e72920b4c61bad6214ebc5deea8f;hpb=7bb07fb5e28756fa13ba5190e6c39003c84d3e1e diff --git a/NEWS.rst b/NEWS.rst index 19aacfbf..5bc827bb 100644 --- a/NEWS.rst +++ b/NEWS.rst @@ -32,7 +32,9 @@ Security Improvements to generate a new FURL, delete the existing ``introducer.furl`` file and restart it. After doing this, the ``[client]introducer.furl`` setting of every client and server that should connect to that introducer must be - updated. (`#1802`_) + updated. Note that other users of a shared machine may be able to read + ``introducer.furl`` from your ``tahoe.cfg`` file unless you configure the + file permissions to prevent them. (`#1802`_) - Both ``introducer.furl`` and ``helper.furl`` are now censored from the Welcome page, to prevent users of your gateway from learning enough to create gateway nodes of their own. For existing guessable introducer