Re: SDI: Secure Semantic Data Injection

Dominik Vogt <[email protected]> Sun, 17 May 2026 22:58:09 +0100
Newsgroups gmane.comp.shells.zsh.user
Message-ID <ago58SUfy7JQ6Lr3@localhost>
On Sun, May 17, 2026 at 08:41:01PM +0000, Jessica Mulein wrote:
> I developed a thing called ?SDI? or "Secure Semantic Data
> Injection? and added it to BSH.

The example command from the web site

  $ printf '{"username":"alice","password":"s3cr3t","ttl":300}' | ...

puts a plain text copy of the user's password in the zsh history
file which is possibly world readable.

Ciao

Dominik ^_^  ^_^

=2D-=20

Dominik Vogt