Re: SDI: Secure Semantic Data Injection
Dominik Vogt <[email protected]> Sun, 17 May 2026 22:58:09 +0100
| Newsgroups | gmane.comp.shells.zsh.user |
|---|---|
| Message-ID | <ago58SUfy7JQ6Lr3@localhost> |
On Sun, May 17, 2026 at 08:41:01PM +0000, Jessica Mulein wrote:
> I developed a thing called ?SDI? or "Secure Semantic Data
> Injection? and added it to BSH.
The example command from the web site
$ printf '{"username":"alice","password":"s3cr3t","ttl":300}' | ...
puts a plain text copy of the user's password in the zsh history
file which is possibly world readable.
Ciao
Dominik ^_^ ^_^
=2D-=20
Dominik Vogt