Johannes,
Your points make sense, thank you for clarifying, it helps
me understand what the underlying concerns are. The attitude doesn't really
help.
Does Junio's counter solution where git would prompt for the
password if the username contained a url solve your concerns with unsecure
config variables? The patch would be just a bugfix to current functionality.
Also, libcurl does not warn you that you have an insecure netrc file.
Just tried it with 7.19.4 on cygwin and FC9.
Thanks for the feedback,
Mike