You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Earthdata documentation may recommend using .netrc files to store credentials, but those files are still plaintext files. They do provide security advantages by mapping credentials to hostnames, but that doesn't negate the security concern of exposing the credentials.
Storing credentials in plaintext is especially problematic when we're training users (who are not security experts) to work on untrusted/shared machines/filesystems in the cloud and on JupyterHubs.
IMO, we should default to persisting only tokens!
The text was updated successfully, but these errors were encountered:
mfisher87
changed the title
Do not save credentials in plaintext
Do not save credentials in plaintext (at least, not by default)
Dec 18, 2023
mfisher87
changed the title
Do not save credentials in plaintext (at least, not by default)
Do not save credentials in plaintext (at least, not as the default persistence mode)
Dec 18, 2023
Earthdata documentation may recommend using .netrc files to store credentials, but those files are still plaintext files. They do provide security advantages by mapping credentials to hostnames, but that doesn't negate the security concern of exposing the credentials.
Storing credentials in plaintext is especially problematic when we're training users (who are not security experts) to work on untrusted/shared machines/filesystems in the cloud and on JupyterHubs.
IMO, we should default to persisting only tokens!
The text was updated successfully, but these errors were encountered: