Stop leaking IB password to IBC log when passed via env vars#359
Open
pps83 wants to merge 1 commit into
Open
Conversation
TWSUSERID/TWSPASSWORD (or /User:/PW:) ended up in clear in every launch's System Properties dump. Config-file IbLoginId/IbPassword was unaffected.
Contributor
Author
|
@rlktradewright ping. current ibc logs password in clear text in its logs if password is passed via env vars |
Member
|
I haven't forgotten this, or the raft of other issues you raised. But at the moment I have more important things to do. Not ideal, I know, but it's been this way for about 23 years and no one has complained about their credentials being compromised becuase of this. Partly because I suspect few users do this, especially as they are warned not to. I want to do one final release of IBC before I abandon it which will include all this stuff and some other things I've had in the pipeline for a while now. I just need to find some time to do it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TWSUSERID/TWSPASSWORD (or /User:/PW:) ended up in clear in every launch's System Properties dump. Config-file IbLoginId/IbPassword was unaffected.