git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git ransom campaign incident report - May 2019

From
Martin Langhoff <martin.langhoff@gmail.com>
Date
May 17, 2019, 23:13 UTC
Message-ID
<CACPiFC+=co2-yGwoiKqr1qSu8dLmVQZ5NxfbdwOr7xz=a7xpdA@mail.gmail.com>
In-Reply-To
<20190517222031.GA17966@sigill.intra.peff.net>
On Fri, May 17, 2019 at 6:20 PM Jeff King <peff@peff.net> wrote:
> I hate the magical-ness of 3b, because credential-store really _isn't_
> the best choice. It's just better than the current behavior. At the same
> time, by doing it automatically, the existing flow they were using just
> works, and is moderately better.

Quite a bit better. It sits in a different directory, and with tight permissions.

Overall -- thank you! That's the process I was picturing. Even just scrubbing the credentials -- your "step 1" -- would be a significant improvement, if a bit unfriendly.

Show 6 quoted lines
> > Judging from looking at my own automated jobs, it does not appear that you
> > would *ever* need to store such credentials in the Git config, anyway. If
> > you need to, say, push to a repository, you can always store the full URL
> > (or the credentials) in a secret variable.
>
> Yes, that's definitely the way you _should_ do it. I think the problem

The key thing are the credentials, and there are much better solutions for this -- ssh keys, etc.

This isn't for thoughtful users, this is to save unaware users from themselves. Maybe they'll and hurt themselves with something else, but that's part of removing sharp edges from a product.

cheers,
m
--
 martin.langhoff@gmail.com
 - ask interesting questions  ~  http://linkedin.com/in/martinlanghoff
 - don't be distracted        ~  http://github.com/martin-langhoff
   by shiny stuff
Previous: Jeff KingNext: Jeff King
Message 6 of 23 in “Git ransom campaign incident report - May 2019”
  1. Martin LanghoffMay 15, 2019
  2. Ævar Arnfjörð BjarmasonMay 15, 2019
  3. Jeff KingMay 16, 2019
  4. Johannes SchindelinMay 17, 2019
  5. Jeff KingMay 17, 2019
  6. Martin LanghoffMay 17, 2019
  7. Jeff KingMay 19, 2019
  8. 1/3 transport_anonymize_url(): support retaining usernameJeff King, May 19, 2019
  9. Eric SunshineMay 19, 2019
  10. René ScharfeMay 20, 2019
  11. Johannes SchindelinMay 20, 2019
  12. Johannes SchindelinMay 20, 2019
  13. 2/3 clone: avoid storing URL passwords in configJeff King, May 19, 2019
  14. 3/3 clone: auto-enable git-credential-store when necessaryJeff King, May 19, 2019
  15. Eric SunshineMay 20, 2019
  16. Jeff KingMay 20, 2019
  17. Johannes SchindelinMay 20, 2019
  18. Ævar Arnfjörð BjarmasonMay 20, 2019
  19. Jeff KingMay 20, 2019
  20. Ævar Arnfjörð BjarmasonMay 20, 2019
  21. Jeff KingMay 20, 2019
  22. Ævar Arnfjörð BjarmasonMay 20, 2019
  23. Johannes SchindelinMay 20, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.