duplicity-talk
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Duplicity-talk] new ftp backend


From: Kenneth Loafman
Subject: Re: [Duplicity-talk] new ftp backend
Date: Fri, 06 Jul 2007 20:49:54 -0500
User-agent: Thunderbird 1.5.0.12 (X11/20070604)

Thorsten Schnebeck wrote:
> Hi,
> 
>> Also, really important: please change it so that is does not use the
>> account data (login and password) as arguments for a process. It's
>> possible to see such things from a "normal" shell account (AFAIK) and
>> therefor I consider this a real bad issue. It should get changed to
>> write the login+password to a protected file and use this instead.
> 
> Yes, that would be the -f parameter every ncftp tool understands. The 
> constructor __init__ can create a temporary user read/write-only file and if 
> python has something like a destructor there it can be deleted. :-)
> 
> While nsftp hides the username and password in its ps/top output the command 
> starts in a separate shell and there you can see it.

I'll address this during the integration.  That was a good catch.

...Ken




reply via email to

[Prev in Thread] Current Thread [Next in Thread]