Re: [Fwd: Bug#258392: lftp should support encrypted passwords in bookmarks]
Glenn Maynard <[email protected]>
| Newsgroups | gmane.network.lftp.devel |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Aug 12, 2004 at 12:03:43AM +0200, Nicolas Noble wrote: > "Crypting" lftp's bookmark would be about the same as the actual > ~~/.cvspass crypto: that is, a non efficient algorithm, which wouldn't > prevent any sysadmin to uncrypt it. Or it would require typing an > uncrypting password every time you launch lftp. What good would that be ? Encrypting stored passwords is extremely useful, because it prevents accidental viewing (eg. if I show somebody my bookmark list by catting ~/.lftp/bookmarks). I wouldn't want the whole URL to be encrypted, though; that's just annoying. "Obfuscated" is a better word than "encrypted", since the latter gives a false sense of security. A real password cache would be a lot more useful, though. I'm constantly having to manually insert usernames and passwords into dynamic easynews URLs: "que get *paste*", back up, insert "glenn:abcdefg@" manually--time- consuming and causing my password to be displayed in plain view on the screen. -- Glenn Maynard