bug#8069: 23.2.94; auth-source should support ~/.netrc by default
Your message dated Thu, 30 Jun 2011 02:12:16 +0200
regarding 23.2.94; auth-source should support ~/.netrc by default
Subject: 23.2.94; auth-source should support ~/.netrc by default Date: Thu, 17 Feb 2011 22:14:53 +0000
auth-source is trying to encourage users to use ~/.authinfo rather than
~/.netrc. This is fine. But many programs and libraries still use
~/.netrc (personally, until reading the auth-source manual I had not
heard of ~/.authinfo).

auth-source also wants to encourage users to encrypt their ~/.authinfo
file (indeed, by default it searches ~/.authinfo.gpg, not ~/.authinfo).
The manual actually says “the auth-source library encourages this
confusion”. It is not a good idea to encourage confusion (even if this
remark is made tongue-in-cheek, auth-source’s current behaviour does
indeed encourage confusion).

Hence, I suggest that with a bit of psychological carrot and stick,
auth-source could get closer to its goal:

Carrot: Default to searching ~/.netrc (unencrypted), ~/.authinfo
(unencrypted), and ~/.authinfo.gpg (encrypted). This means that users
with an unencrypted file or old-name file are not annoyed. By all means
create a symlink from ~/.authinfo to ~/.netrc if the former doesn’t
already exist, and don’t actually search ~/.netrc. (But maybe that would
create potential security problems of its own.)

Stick: Display a minibuffer warning message when an unencrypted file is
found. Thus, the user is not actually interrupted (which breeds
annoyance), but does receive a gentle reminder that encrypted is better.

(You could display a more urgent message, or interrupt the user, if a
world-readable authorisation file is found.)

Note that this suggestion does not affect users who have already
migrated to ~/.authinfo{,.gpg}.

Subject: Re: bug#8069: 23.2.94; auth-source should support ~/.netrc by default Date: Thu, 30 Jun 2011 02:12:16 +0200
Lars Magne Ingebrigtsen <address@hidden> writes:

> But, yes, I think ~/.netrc should be added to the list of auth sources
> to consult.

This has been fixed in No Gnus now.

(domestic pets only, the antidote for overdose, milk.)
  bloggy blog http://lars.ingebrigtsen.no/

