Skip to content

ReplyToThis could offer more secure advice #1843

Description

@dseomn

https://github.com/gitgitgadget/gitgitgadget/wiki/ReplyToThis has a command that puts a password in the command line:

curl -g --user "<email>:<password>" --url "imaps://imap.gmail.com/INBOX" -T /path/to/raw.txt

https://www.netmeister.org/blog/passing-passwords.html has a decent overview of the security issues with that.

Since this is interactive, this looks like the easiest alternative: https://curl.se/docs/manpage.html#-u

If you simply specify the username, curl prompts for a password.

Activity

  1. dscho commented on Mar 3, 2025

    @dscho
    Member

    Since this is interactive, this looks like the easiest alternative: https://curl.se/docs/manpage.html#-u

    I don't quite understand... Do you mean to replace --user <email>:<password> with --user <email>?

  2. dseomn commented on Mar 3, 2025

    @dseomn
    Author

    Yup, exactly. That way curl can read the password from stdin (or the tty, or however it does it).

  3. dscho commented on Mar 3, 2025

    @dscho
    Member

    @dseomn I hope to merge gitgitgadget/gitgitgadget.github.io#21 soon, after that I'd like to invite you to contribute the change via a PR (I do like a development process that uses modern tools such as PRs...)

  4. dseomn commented on Mar 3, 2025

    @dseomn
    Author

    Sure, I just subscribed to that so I'll know when it's merged, but feel free to ping me if I forget. (I did look for an edit button on the wiki before filing this bug.)

  5. dscho commented on Mar 4, 2025

    @dscho
    Member

    I did look for an edit button on the wiki before filing this bug.

    Yeah, that's my fault. I just got too tired with the spam fighting in Git for Windows' wiki and simply locked down GitGitGadget's wiki.

  6. added a commit that references this issue on Mar 6, 2025
    895f851
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions