On Thu, Jul 03, 2008 at 08:45:02AM +0000, Mattias Wingstedt (Firefruit) @ Pike (-) developers forum wrote:
On the other hand, the existence of both a secure and a non-secure string with the same contents is clear evidence that the security model has been broken.
that is only true if both strings come from the same source. in a multiuser environment this is not necesarily the case.
greetings, martin.