3 ms·
Program args can be seen with tools like 'ps', so passing credentials that way is a poor choice.
by fullstop 1y ago
Program args can be seen with tools like 'ps', so passing credentials that way is a poor choice.
- sureglymop 1y agoWell yeah of course. What you could do though would be to have e.g. --secrets-file and at startup time the application reads that file to get the secret. Then you could use file permissions to make sure only the (application) user running the application can read that file (or even more extreme, the application destroys the file after reading it). I think that would still be better than env vars, which are more likely to leak somewhere you didn't intend them to.
- hinkley 1y agoThey can also be caught by bash and system audit logs.
- darrenf 1y agoFWIW, environment variables (edit: of your own processes) can also be seen with `ps`. ps wwwex | grep [w]wwex 31109 pts/0 R+ 0:00 ps wwwex GDM_LANG=en_GB.utf8 STARSHIP_SHELL=fish GDMSESSION=xfce STARSHIP_SESSION_KEY=2904922223926273 XDG_CURRENT_DESKTOP=XFCE LC_NUMERIC=en_GB.UTF-8 TERMINFO=/usr/share/terminfo LC_MONETARY=en_GB.UTF-8 SHELL=/bin/fish LC_ADDRESS=en_GB.UTF-8 ... many, many more ...
- fullstop 1y agoRight, you can see your own environment variables. Root can see your environment variables. Another user can not. edit: submitted before I saw your edit. :-)