vscode-sftp icon indicating copy to clipboard operation
vscode-sftp copied to clipboard

Risk of sftp.json file being posted on line compromising passwords

Open MHPAP opened this issue 8 months ago • 0 comments

Is this a similar or duplicate feature request?

  • [ ] I don't know. I will go check it.
  • [ X] No.

**If you transfer your website to another host, copying all the files create a copy of the sftp.json file on line. Malicious people scan for those files to steal passwords and take control of the websites. I did it (shame on me - error is human - if something can go wrong it will) an was quickly attacked.

**All the passwords should be stored locally outside the website structure, like one level up, to reduce the risk of posting passwords on line inadvertently.

**Alternatively, encrypting the passwords or the sftp.json file

Does this project help you?

  • [x] Yes. SFTP IS AWESOME!

MHPAP avatar Mar 14 '25 11:03 MHPAP