commons-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Ralf Hauser (JIRA)" <j...@apache.org>
Subject [jira] Commented: (IO-70) [io] Add a secureDelete method to FileUtils.java
Date Mon, 01 Oct 2007 11:09:50 GMT

    [ https://issues.apache.org/jira/browse/IO-70?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#action_12531471
] 

Ralf Hauser commented on IO-70:
-------------------------------

"COM-1711"  now is FILEUPLOAD-85

> [io] Add a secureDelete method to FileUtils.java
> ------------------------------------------------
>
>                 Key: IO-70
>                 URL: https://issues.apache.org/jira/browse/IO-70
>             Project: Commons IO
>          Issue Type: Improvement
>          Components: Utilities
>         Environment: Operating System: other
> Platform: All
>            Reporter: Ralf Hauser
>            Priority: Minor
>             Fix For: 1.3
>
>
> in org.apache.commons.io.FileUtils
> Commons Fileupload uses at least the io's FileCleaner.track() method.
> Unfortunately, they just use the plain java File.delete() method and not a more
> sophisticated delete as offered in this package.
> Especially, if servers running the FileUpload are sitting in DMZs and forward
> all personal/private uploaded information in another (DB-)server behind another
> firewall, one would not want that if the DMZ machine gets hacked, all previous
> uploads that are supposedly deleted still can easily be found on the disk by a
> not even that skilled attacker.
> Therefore, it would be great to have a pgp-wipe alike secure delete method here!
> it would overwrite the file multiple times and probably, it this should be
> spawned as a separte thread since that may take longer than a state-of-the-art
> GUI would want to wait for such an action to complete.

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


Mime
View raw message