Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upEmergency backup recovery instructions should warn user about passwords in shell history and process list #1967
Comments
andrewdavidwong
added
enhancement
C: doc
P: major
privacy
labels
May 6, 2016
andrewdavidwong
added this to the
Documentation/website milestone
May 6, 2016
andrewdavidwong
added
P: minor
and removed
P: major
labels
May 17, 2016
andrewdavidwong
added
the
help wanted
label
Mar 18, 2018
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
defuse commentedMay 6, 2016
The Emergency Backup Recovery documentation instructs the reader to type their password into command-line arguments without mentioning that it'll be saved in their shell history and will be visible in the process list while the commands are running. Add those warnings, or switch to different tools that don't have these vulnerabilities (#971).