duplicity-talk
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Duplicity-talk] Manifest stores SHA1 hash of files, checked before


From: edgar . soldin
Subject: Re: [Duplicity-talk] Manifest stores SHA1 hash of files, checked before restore?
Date: Thu, 14 Jul 2011 15:26:29 +0200
User-agent: Mozilla/5.0 (Windows NT 5.1; rv:5.0) Gecko/20110624 Thunderbird/5.0

On 14.07.2011 15:03, Kenneth Loafman wrote:
>>     why don't we simply show the password and circumvent the need for 
>> verification?
>> 
>>    also we should have a check if gpg receiver[0] == sign_key[0], so the 
>> pass is not asked two times for the same key on simple one key only setups.
> 
> 
> Showing the password is a security risk, but maybe we could put in an option.

on the other hand users can do 
PASSPHRASE='whoa_secret' duplicity ...
which would of course land in the users history (which is bad).

if you think the retype is necessary, let's leave it, people will complain if 
it really bothers. duplicity's target still is the cron runabilility.

> 
> Checking for the same keys would be a good enhancement.

will try to provide a branch for that, also the SIGN_PASSPHRASE change should 
get documented in manpage.

ede/duply.net



reply via email to

[Prev in Thread] Current Thread [Next in Thread]