Educause Security Discussion mailing list archives

Looking for SSH/SCP/SFTP/FTP client that does not store passwords


From: Gary Flynn <flynngn () JMU EDU>
Date: Thu, 18 Jun 2009 10:56:28 -0400

Hi,

Anyone know off the top of their head of an SSH/SCP/FTP/SFTP client
that can be configured and distributed in a way that won't allow
server/password pairs to be stored?

FileZilla is being proposed but not only does it store by default
but it also stores in cleartext.

Given the recent malware that used locally stored FTP passwords
to compromise web sites and the long history of stored SSH keys
being used to leapfrog into systems, I'd prefer to use a client
with more sane and conservative settings and features on desktops
of web publishers and system administrators.


--
Gary Flynn
Security Engineer
James Madison University
www.jmu.edu/computing/security

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature


Current thread: