+**This release fixes an important security hole, upgrade immediately.**
+
News for ikiwiki 2.48:
If you allowed password based logins to your wiki, those passwords were
* The password\_cost config setting is provided as a "more security" knob.
* teximg: Fix logurl.
* teximg: If the log isn't written, avoid ugly error messages.
- * Updated French translation. Closes: #[478530](http://bugs.debian.org/478530)"""]]
\ No newline at end of file
+ * Updated French translation. Closes: #[478530](http://bugs.debian.org/478530)"""]]
You might also consider changing to [[plugins/openid]], which does not
require ikiwiki deal with passwords at all, and does not involve users sending
passwords in cleartext over the net to log in, either.
+
+## Empty password security hole
+
+This hole allowed ikiwiki to accept logins using empty passwords, to openid
+accounts that didn't use a password. It was introduced in version 1.34, and
+fixed in version 2.48. The [bug](http://bugs.debian.org/483770) was
+discovered on 30 May 2008 and fixed the same day.
+
+I recommend upgrading to 2.48 immediatly if your wiki allows both password
+and openid logins.