password is stored in the system config (which is fine) but we need to reject all attempts at logging in with an error message 'password file is world readable' if anyone but the user can read it.
Log in to post a comment.