logoalt Hacker News

rcxdudeyesterday at 8:17 AM1 replyview on HN

They would still exist in plaintext, just the permissions would make it a little harder to access.


Replies

otabdeveloper4yesterday at 11:55 AM

No, UNIX sockets work over SSL too.

You can, theoretically, decompile the system memory dump and try to mine the credentials out of the credential server's heap, but that exploit is exponentially more difficult to do that a simple `cat /proc/1234/environ`.