How secure is git credential caching with `git config --global credential.helper 'cache`?

Viewed 1026

How does using git HTTPS credential caching with git config --global credential.helper 'cache compare vs. using git SSH key authentication security wise?

The documentation for git credential.helper cache says:

The stored credentials never touch the disk, and are forgotten after a configurable timeout. The
cache is accessible over a Unix domain socket, restricted to the current user by filesystem permissions.

I found that you can view the HTTPS cache credentials with echo url=https://[example.com] | git credential fill. Not sure about the security implications of this vs using SSH keys. If somebody else SSH-ed into the same device (as a different user with different SSH keys), would they also be able to view the credentials, or because they are a different user, they would not be able to view the credentials this way?

Given that with both methods, if somebody gains access to your system and assumes your user, they can view the passwords or SSH keys, is it correct to say that the HTTPS authentication is generally more secure because it I) expires after a given period II) expires with a restart and III) can be configured to only scoped permissions for certain git actions?

1 Answers

If somebody else SSH-ed into the same device (as a different user with different SSH keys), would they also be able to view the credentials

No, since, as the documentation mentions, the cache is accessible over a Unix domain socket, restricted to the current user by filesystem permissions.

compare vs. using git SSH key authentication security wise?

SSH keys means you are not typing a password.
To achieve the same with HTTPS, it is better to use a persistent cache, rather than a temporary one, where you need to type the password at each session.

The latest one would be GCM-core: Git Credential Manager Core.
It needs to be installed, but once git config credential.helper is set to manager-core, it will store the password (for a given URL) in a secure local vault, using libscret to communicates with the "Secret Service" using D-Bus (gnome-keyring and ksecretservice are both implementations of a Secret Service.)

Related