Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do not save credentials in plaintext (at least, not as the default persistence mode) #415

Open
mfisher87 opened this issue Dec 18, 2023 · 0 comments
Labels
enhancement New feature or request

Comments

@mfisher87
Copy link
Collaborator

mfisher87 commented Dec 18, 2023

Earthdata documentation may recommend using .netrc files to store credentials, but those files are still plaintext files. They do provide security advantages by mapping credentials to hostnames, but that doesn't negate the security concern of exposing the credentials.

Storing credentials in plaintext is especially problematic when we're training users (who are not security experts) to work on untrusted/shared machines/filesystems in the cloud and on JupyterHubs.

IMO, we should default to persisting only tokens!

@mfisher87 mfisher87 added the enhancement New feature or request label Dec 18, 2023
@mfisher87 mfisher87 changed the title Do not save credentials in plaintext Do not save credentials in plaintext (at least, not by default) Dec 18, 2023
@mfisher87 mfisher87 changed the title Do not save credentials in plaintext (at least, not by default) Do not save credentials in plaintext (at least, not as the default persistence mode) Dec 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: 🆕 New
Development

No branches or pull requests

1 participant