How does using git HTTPS credential caching with git config --global credential.helper 'cache compare vs. using git SSH key authentication security wise?
The documentation for git credential.helper cache says:
The stored credentials never touch the disk, and are forgotten after a configurable timeout. The
cache is accessible over a Unix domain socket, restricted to the current user by filesystem permissions.
I found that you can view the HTTPS cache credentials with
echo url=https://[example.com] | git credential fill. Not sure about the security implications of this vs using SSH keys. If somebody else SSH-ed into the same device (as a different user with different SSH keys), would they also be able to view the credentials, or because they are a different user, they would not be able to view the credentials this way?
Given that with both methods, if somebody gains access to your system and assumes your user, they can view the passwords or SSH keys, is it correct to say that the HTTPS authentication is generally more secure because it I) expires after a given period II) expires with a restart and III) can be configured to only scoped permissions for certain git actions?