Better password security in GitHub for Windows
We’re always looking at ways to improve security. Today’s release of GitHub for Windows (version 1.0.54) improves password handling security through the use of OAuth tokens. Prior to this release…
We’re always looking at ways to improve security. Today’s release of
GitHub for Windows (version 1.0.54) improves password handling security
through the use of OAuth tokens.
Prior to this release the application would encrypt and store your password.
Since the application also registers itself as your Git credential provider,
the app would provide your credentials in clear text to Git.exe whenever it
asked for them.
With this release, when you log in with your username and password, the
application registers itself on GitHub.com as an Authorized application and
receives an OAuth token that it stores instead of your password. This is
similar to how other applications that integrate with GitHub work such as
Travis-CI.
Go to your account settings and click the Applications tab
to see a list of authorized applications.
For a while now, GitHub has supported using Git over HTTPS with an OAuth token.
Now, when Git requires your credentials, GitHub for Windows passes your OAuth
token to Git.
One benefit of this approach is if someone steals your laptop, you can just
go to the Applications tab and click the Revoke button to invalidate the
current OAuth token. The thief can’t retrieve your password from the contents
of your hard-drive. The next time you log in, GitHub for Windows registers
itself again and receives a newly generated OAuth token. Of course in this
situation, it’s still a good idea to change your password.
Enjoy more secure access to your GitHub account!
Written by
Related posts
data:image/s3,"s3://crabby-images/37040/37040247fc4b3eeda5ea4f5c7746d41dd5147ff8" alt=""
GitHub Availability Report: January 2025
In January, we experienced two incidents that resulted in degraded performance across GitHub services.
data:image/s3,"s3://crabby-images/13490/134904f05eae695cf016961aa1351e371c983ce1" alt="GitHub Copilot agent mode"
GitHub Copilot: The agent awakens
Introducing agent mode for GitHub Copilot in VS Code, announcing the general availability of Copilot Edits, and providing a first look at our SWE agent.
data:image/s3,"s3://crabby-images/80c8b/80c8b2f9d2fcb05a6e0e54b2f4baf357d2a9ee51" alt=""
That’s a wrap: GitHub Innovation Graph in 2024
Discover the latest trends and insights on public software development activity on GitHub with the release of Q2 & Q3 2024 data for the Innovation Graph.