3 ms·
What’s the threat model? If an attacker has access to your shell history then don’t they then already have access to basically everything else?
by bomewish 2y ago
What’s the threat model? If an attacker has access to your shell history then don’t they then already have access to basically everything else?
- leetrout 2y agoNo, not necessarily. Compared to interactive prompts / processes, at a minimum ones that can help audit access (e.g. 1password), there is an immediate layer of defense missing when things are just sitting in plain text in the history. (Same extends to our beloved `.env` files.) If you do a lot of remote pairing or screen sharing then you also remove the risk of sharing on accident by searching or walking up through your command history.