You are not logged in.

#1 2008-04-21 01:00:19

synthead
Member
From: Seattle
Registered: 2006-05-09
Posts: 1,319

~/.aurvote and passwords

I don't really want to store my password for the AUR in plaintext within ~/.aurvote.  Is there a way I could hash it for ~/.aurvote or something?

Last edited by synthead (2008-04-22 09:24:17)


Touch my kernel

Offline

#2 2008-04-22 20:17:26

synthead
Member
From: Seattle
Registered: 2006-05-09
Posts: 1,319

Re: ~/.aurvote and passwords

bump


Touch my kernel

Offline

#3 2008-04-22 21:52:56

aRcHaTe
Member
Registered: 2006-10-24
Posts: 644

Re: ~/.aurvote and passwords

i dont think so....


Its a sick world we live in....

Offline

#4 2008-04-23 09:02:51

DonVla
Member
From: Bonn, Germany
Registered: 2007-06-07
Posts: 996

Re: ~/.aurvote and passwords

synthead wrote:

I don't really want to store my password for the AUR in plaintext within ~/.aurvote.  Is there a way I could hash it for ~/.aurvote or something?

chmod 600 ~/.aurvote, move file to a truecrypt encrypted partition, then use gpg. security first big_smile


pkgman - the ultimate mosquito control (AUR)

Offline

#5 2008-04-23 09:42:29

iphitus
Forum Fellow
From: Melbourne, Australia
Registered: 2004-10-09
Posts: 4,927

Re: ~/.aurvote and passwords

You could always patch aurvote.

Offline

#6 2008-04-23 14:43:41

carlocci
Member
From: Padova - Italy
Registered: 2008-02-12
Posts: 368

Re: ~/.aurvote and passwords

synthead wrote:

I don't really want to store my password for the AUR in plaintext within ~/.aurvote.  Is there a way I could hash it for ~/.aurvote or something?

If you hash it how would you go back to your key from the hash?
You could encrypt it, but then you would have to use a password to decode it runtime.
Being a bash script, you can easily patch aurvote for asking your password at runtime, I believe.
Just add something like

echo "Insert password"
read PASS

when your .aurvote is sourced.
This way you'll have to enter your password everytime though.

Offline

#7 2009-06-21 17:19:23

EvilSnowball
Member
Registered: 2009-06-20
Posts: 4

Re: ~/.aurvote and passwords

You could create a separate file – say, ~/auracc – containing something like this:

user:yourUserName
pass:yourPassword

This file could be made readable/writable only by root.  Then your ~/.aurvote file could look like this:

user=$(sudo grep "user" ~/auracc | cut -d":" -f2)
pass=$(sudo grep "pass" ~/auracc | cut -d":" -f2)

EDIT: Whoa... Oops!  Looks like this thread was over a year old.  I thought I saw "2009" where it said "2008".  I guess I didn't look at the date long enough...

Last edited by EvilSnowball (2009-06-22 00:43:48)

Offline

#8 2010-05-27 20:57:46

trusktr
Member
From: Sacramento, CA
Registered: 2010-02-18
Posts: 894
Website

Re: ~/.aurvote and passwords

I think the easiest thing is just make some random username and password you will never use for anything else, just for aurvote.

Problem solved. wink

I mean, seriously, if someone steals your aurvote credentials, what are they gunna do? Go around voting for everything? What a waste of time! tongue

Offline

#9 2010-05-27 21:19:46

j.roszk
Member
From: Poznan/Poland
Registered: 2008-05-22
Posts: 29
Website

Re: ~/.aurvote and passwords

Someone can put some nasty lines into your PKGBUILDS.

Offline

#10 2010-06-29 21:28:25

misc
Member
From: Bavaria, Germany
Registered: 2010-03-22
Posts: 105

Re: ~/.aurvote and passwords

edit: Nevermind, it's in ~/.config .

Last edited by misc (2010-06-29 21:37:20)

Offline

#11 2011-08-12 02:35:02

ricardofunke
Member
Registered: 2009-11-03
Posts: 33

Re: ~/.aurvote and passwords

Yeah I know that is being a long time, but here's my solution:

I put this lines in the .config/aurvote file:

$ cat .config/aurvote
read -p 'Username: ' user
read -s -p 'Password: ' pass
echo

And it works flawlessly! But I think it should be directly in the aurvote code instead of asking you to make that dumb insecure file

Offline

#12 2011-08-16 14:40:46

fsckd
Forum Moderator
Registered: 2009-06-15
Posts: 3,077

Re: ~/.aurvote and passwords

I'm going to go ahead and close this. Whatever answers that could be given have already been given.

I've split the generic discussion on password storage into a new thread found here: https://bbs.archlinux.org/viewtopic.php?pid=976879


aur S & M :: forum rules :: Community Ethos
Resources for Women, POC, LGBT*, and allies

Offline

Board footer

Powered by FluxBB