Re: [PATCH] contrib: add a pair of credential helpers for Mac OS X's keychain
- From
John Szakmeister <john@szakmeister.net>
- Date
- Sep 30, 2011, 01:17 UTC
- Message-ID
- <CAEBDL5VbaafKYjJc6spgz94Z4R7QprA7vFPMGWhgk5QY99-wBQ@mail.gmail.com>
- In-Reply-To
- <CAEBDL5WhpVg17aPuRqrE5=2Q293kVD4fYtxGqRzx_K=87t-jgw@mail.gmail.com>
On Thu, Sep 29, 2011 at 6:03 AM, John Szakmeister <john@szakmeister.net> wrote: [snip]
> Yep, I agree. And it's worse when using the security command line > tool... when you grant security access to the key, then any app could > technically gain access to the item via the security tool. That's one > of the reasons I didn't pursue that route early on.
Thinking about this a little more, git-credential-anything has the same problem. I can run it, and it'll dump out my password for anybody. I'd rather it didn't do that. I think it would be more satisfying to have the mechanisms built into git itself, without a separate application. I'm not sure how practical that is though.
-John