git/list[1] front-page[2] threads[3] people[4] search[5] about
 

The enduring popularity of git-credential-store

From
M Hickford <mirth.hickford@gmail.com>
Date
Nov 8, 2022, 10:50 UTC
Message-ID
<CAGJzqskRYN49SeS8kSEN5-vbB_Jt1QvAV9QhS6zNuKh0u8wxPQ@mail.gmail.com>

Among StackOverflow users [1], git-credential-store appears several times more popular than any other credential helper. Does this make anyone else uneasy? The docs warn that git-credential-store "stores your passwords unencrypted on disk" [2]. Are users sacrificing security for convenience?

Firstly, how grave is storing credentials in plaintext? Software development guidelines such as CWE discourage storing credentials in plaintext [3]. Password managers in desktop environments, mobile operating systems and web browsers typically encrypt passwords on disk and guard them behind a master password.

Secondly, the docs recommend git-credential-cache [2] which ships with Git and is equally easy to configure. So why isn't it more popular? My hypothesis: while caching works great for passwords typed from memory, the combination of caching with personal access tokens has poor usability. The unmemorised token is lost when the cache expires, so the user has to generate a new token every session. I suspect GitHub's 2021 decision to stop accepting passwords [4] may have inadvertently pushed users from 'cache' to 'store'.

Thirdly, why doesn't everyone use SSH keys? Unlike HTTP remotes, upfront set-up is necessary to clone a public repo. For users unfamiliar with SSH, this set-up may be intimidating. Introducing users new to Git to SSH at the same time is a significant cognitive load.

Any ideas how to improve the security of the average Git user?
[1] https://stackoverflow.com/questions/35942754/how-can-i-save-username-and-password-in-git
 probably as good a survey of non-expert users as we can get
[2] https://git-scm.com/docs/git-credential-store
[3] https://cwe.mitre.org/data/definitions/256.html
[4] https://github.blog/2020-12-15-token-authentication-requirements-for-git-operations/
[5] https://lore.kernel.org/git/20111210103444.GL16529@sigill.intra.peff.net/t/#u
discussion at introduction of store helper
Next: Michal Suchánek
Message 1 of 13 in “The enduring popularity of git-credential-store”
  1. M HickfordNov 8, 2022
  2. Michal SuchánekNov 8, 2022
  3. Jeff KingNov 8, 2022
  4. Taylor BlauNov 8, 2022
  5. M HickfordFeb 11, 2023
  6. brian m. carlsonNov 8, 2022
  7. M HickfordNov 12, 2022
  8. Matthew John CheethamNov 17, 2022
  9. Jeff KingNov 17, 2022
  10. Lessley DenningtonNov 17, 2022
  11. Jeff KingNov 17, 2022
  12. M HickfordMay 29, 2023
  13. M HickfordMay 28, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.