{"thread":{"id":"49797","subject":"BUG REPORT: git clone of non-existent repository results in request for credentials","startedAt":"2018-11-11T09:40:06Z","lastAt":"2018-11-11T18:01:02Z","messageCount":3,"participants":["Federico Lucifredi","Ævar Arnfjörð Bjarmason"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"362932","messageId":"708E1759-B2E3-436C-9D54-214159655B1B@acm.org","threadId":"49797","inReplyTo":null,"subject":"BUG REPORT: git clone of non-existent repository results in request for credentials","fromName":"Federico Lucifredi","fromEmail":"flucifredi@acm.org","sentAt":"2018-11-11T09:22:52Z","receivedAt":"2018-11-11T09:40:06Z","isPatch":false,"sender":{"key":"flucifredi@acm.org","avatar":"https://gravatar.com/avatar/b79ecef647be321885840be58ccfa3b1051e47b642984f66d2d16d4fd974e4c9?d=mp&s=160"},"body":"git clone of non-existent repository results in request for credentials\n\nREPRODUCING:\nsudo apt install git\ngit clone https://github.com/xorbit/LiFePo4owered-Pi.git    #this repo does not exist\n\nGit will then prompt for username and password on Github.\n\nI can see a valid data-leak concern (one could probe for private repository names in a brute-force fashion), but then again the UX impact is appalling. Chances of someone typing an invalid repo name are pretty high, and this error message has nothing to do with the actual error.\n\nRESOLUTION:\nThe error message should indicate that the repository name does not exist. \n\n\nBest -F\n\n\n\n_________________________________________\n-- \"'Problem' is a bleak word for challenge\" - Richard Fish\n(Federico L. Lucifredi) - flucifredi at acm.org - GnuPG 0x4A73884C\n\n"},{"id":"362944","messageId":"87y39z3ea8.fsf@evledraar.gmail.com","threadId":"49797","inReplyTo":"708E1759-B2E3-436C-9D54-214159655B1B@acm.org","subject":"Re: BUG REPORT: git clone of non-existent repository results in request for credentials","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2018-11-11T14:00:15Z","receivedAt":"2018-11-11T14:02:15Z","isPatch":false,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Sun, Nov 11 2018, Federico Lucifredi wrote:\n\n> git clone of non-existent repository results in request for credentials\n>\n> REPRODUCING:\n> sudo apt install git\n> git clone https://github.com/xorbit/LiFePo4owered-Pi.git    #this repo does not exist\n>\n> Git will then prompt for username and password on Github.\n>\n> I can see a valid data-leak concern (one could probe for private repository names in a brute-force fashion), but then again the UX impact is appalling. Chances of someone typing an invalid repo name are pretty high, and this error message has nothing to do with the actual error.\n>\n> RESOLUTION:\n> The error message should indicate that the repository name does not exist.\n\nThis is a legitimate thing to complain about, but it has nothing to do\nwith git itself maintained on this mailing list, but the response codes\nof specific git hosting websites. E.g. here's two issues for fixing this\non GitLab:\n\nhttps://gitlab.com/gitlab-org/gitlab-ce/issues/50201\nhttps://gitlab.com/gitlab-org/gitlab-ce/issues/50660\n\nThese hosting platforms are intentionally producing bad error messages\nto not leak information, as you note.\n\nSo I doubt it's something they'll ever change, the bug I have open with\nthis on GitLab is to make this configurable for privately run instances.\n"},{"id":"362947","messageId":"C44E4FCB-D968-43E6-82CC-7D2F73D461C7@acm.org","threadId":"49797","inReplyTo":"87y39z3ea8.fsf@evledraar.gmail.com","subject":"Re: BUG REPORT: git clone of non-existent repository results in request for credentials","fromName":"Federico Lucifredi","fromEmail":"flucifredi@acm.org","sentAt":"2018-11-11T18:00:56Z","receivedAt":"2018-11-11T18:01:02Z","isPatch":false,"sender":{"key":"flucifredi@acm.org","avatar":"https://gravatar.com/avatar/b79ecef647be321885840be58ccfa3b1051e47b642984f66d2d16d4fd974e4c9?d=mp&s=160"},"body":"I was afraid that was the reason. Oh well, at least we know why :-)\n\nThanks Ævar!\n\nBest-F\n\n> On Nov 11, 2018, at 9:00 AM, Ævar Arnfjörð Bjarmason <avarab@gmail.com> wrote:\n> \n> \n>> On Sun, Nov 11 2018, Federico Lucifredi wrote:\n>> \n>> git clone of non-existent repository results in request for credentials\n>> \n>> REPRODUCING:\n>> sudo apt install git\n>> git clone https://github.com/xorbit/LiFePo4owered-Pi.git    #this repo does not exist\n>> \n>> Git will then prompt for username and password on Github.\n>> \n>> I can see a valid data-leak concern (one could probe for private repository names in a brute-force fashion), but then again the UX impact is appalling. Chances of someone typing an invalid repo name are pretty high, and this error message has nothing to do with the actual error.\n>> \n>> RESOLUTION:\n>> The error message should indicate that the repository name does not exist.\n> \n> This is a legitimate thing to complain about, but it has nothing to do\n> with git itself maintained on this mailing list, but the response codes\n> of specific git hosting websites. E.g. here's two issues for fixing this\n> on GitLab:\n> \n> https://gitlab.com/gitlab-org/gitlab-ce/issues/50201\n> https://gitlab.com/gitlab-org/gitlab-ce/issues/50660\n> \n> These hosting platforms are intentionally producing bad error messages\n> to not leak information, as you note.\n> \n> So I doubt it's something they'll ever change, the bug I have open with\n> this on GitLab is to make this configurable for privately run instances.\n> \n\n"}]}