git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] credential: warn about git-credential-store [RFC]

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 2, 2025, 23:41 UTC
Message-ID
<xmqqo6zj3ofi.fsf@gitster.g>
In-Reply-To
<20250201025413.GB4088801@coredump.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 19 quoted lines
> On Fri, Jan 31, 2025 at 07:48:06PM +0000, M Hickford via GitGitGadget wrote:
>
>> From: M Hickford <mirth.hickford@gmail.com>
>> 
>> git-credential-store saves secrets unencrypted on disk.
>> 
>> Warn the user before they type their password, suggesting alternative
>> credential helpers.
>> 
>> An alternative could be to warn in "credential-store store". A
>> disadvantage is that the user wouldn't see the warning until after they
>> typed their password, which is less helpful. The warning would appear
>> again every time the user authenticated, which feels too frequently.
>
> I certainly don't disagree that "store" is relatively insecure,
> but...who are we trying to help here? We do not turn on "store" by
> default, so anybody who is running it would had to have explicitly
> configured it as a helper. And there's a big warning already at the top
> of the manpage.

I buy this argument. I think an earlier comment by brian was on a similar wavelength.

Thanks.
Previous: Jeff KingNext: brian m. carlson
Message 4 of 5 in “credential: warn about git-credential-store [RFC]”
  1. credential: warn about git-credential-store [RFC]M Hickford via GitGitGadget, Jan 31, 2025
  2. Junio C HamanoJan 31, 2025
  3. Jeff KingFeb 1, 2025
  4. Junio C HamanoFeb 2, 2025
  5. brian m. carlsonFeb 1, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.