{"thread":{"id":"21737","subject":"insecurity in verify-tag?","startedAt":"2009-11-24T16:56:50Z","lastAt":"2009-11-25T12:54:53Z","messageCount":2,"participants":["David Roundy","Michael J Gruber"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"128249","messageId":"117f2cc80911240856lbbb923buc7d0407bc2cba6a9@mail.gmail.com","threadId":"21737","inReplyTo":null,"subject":"insecurity in verify-tag?","fromName":"David Roundy","fromEmail":"roundyd@physics.oregonstate.edu","sentAt":"2009-11-24T16:56:50Z","receivedAt":"2009-11-24T16:56:50Z","isPatch":false,"sender":{"key":"roundyd@physics.oregonstate.edu","avatar":"https://gravatar.com/avatar/20c6928b273bb8a1c23deb12399d0e74782ce911504ad5ee604294fc6a61940a?d=mp&s=160"},"body":"I've just been looking at the code and I see what looks like a (minor)\nsecurity hole in the verify-tag feature.  In particular, the tag\nverification code doesn't check that the tag is signed by the same\nuser that created the tag.  To be fair, gpg does output the identity\nof the key that created the signature as well as the key used to\ncreate the signature, so an astute user could detect that some\nshenanigans is going on.\n\nAn attack would simply require getting one's own public key into the\nkeyring of a user.  This probably wouldn't be very easy at the moment,\nbut if people were to actually use encrypted email (and if they set\ntheir mail agents to download public keys), it might require no more\nthen sending a signed email to a mailing list.\n\nOf course, you'd also somehow have to trick them into pulling (or\ncloning) your corrupt tag, which probably requires compromising a\nserver (or mirror) somewhere.  But of course, the whole point of\nsigning tags is to eliminate precisely this danger.\n\nWhat should be done about this? First, there ought to be a feature to\nlimit git verify-tag to use a specific keyring.  Maybe there is an\nenvironment variable, and it's just not documented in the man page?\n\nIt would also seem like a good idea to at a minimum check that the\nname/email associated with the signature is the same as that of the\ntagger.  This doesn't gain you *too* much, since an attacker can\nalways create his own key with any name and email he likes, but at\nleast it means that users could feel safe adding keys to their public\nkeyring, as long as those keys have reasonable names/emails associated\nwith them, and as long as they run git show on a tag before trusting\nthat that tag came from a particular person.  i.e. it seems reasonable\nfor me to expect that if I run:\n\n$ git show v1.0\ntag v1.0\nTagger: Linus Torvalds ...\n...\n[user carefully reads the Tagger line...]\n$ git verify-tag v1.0 && make\n\nThat I won't be running make on a repository that wasn't signed by a\nkey that at least *claims* to belong to Linus Torvalds.\n\nThoughts?\n-- \nDavid Roundy\n\n\n\nmkdir temp\ncd temp\ngit init\nInitialized empty Git repository in /tmp/temp/.git/\ndate > foo\ngit add foo\nexport GIT_AUTHOR_NAME=\"Someone else\"\nexport GIT_AUTHOR_EMAIL=\"notme@example.com\"\nexport GIT_COMMITTER_NAME=\"Linus Torvalds\"\nexport GIT_COMMITTER_EMAIL=\"linus@example.com\"\ngit commit -m 'hello world'\nCreated initial commit dc3b7e9: hello world\n 1 files changed, 1 insertions(+), 0 deletions(-)\n create mode 100644 foo\ngit tag -u droundy -m foo v1.0\ngpg: Invalid passphrase; please try again ...\ngpg: Invalid passphrase; please try again ...\n\ngit verify-tag v1.0\ngpg: Signature made Tue 24 Nov 2009 11:41:49 AM EST using DSA key ID D3D5BCEC\ngpg: Good signature from \"David Roundy <roundyd@physics.oregonstate.edu>\"\ngpg:                 aka \"David Roundy <droundy@darcs.net>\"\ngpg:                 aka \"David Roundy <droundy@abridgegame.org>\"\ngpg:                 aka \"David Roundy <daveroundy@gmail.com>\"\n\ngit show v1.0\ntag v1.0\nTagger: Linus Torvalds <linus@example.com>\nDate:   Tue Nov 24 11:41:49 2009 -0500\n\nfoo\n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1.4.9 (GNU/Linux)\n\niEYEABECAAYFAksMDM0ACgkQQ6uZI9PVvOyXFQCgoc4UYfNFYzVH4HduLdh9VUc/\nNSkAn05yr/ARnWGUC8I/OmjhZJEjG5Oa\n=ro48\n-----END PGP SIGNATURE-----\ncommit dc3b7e9f8f5c49bdfe8816abdb4bb392c30e3ef5\nAuthor: Someone else <notme@example.com>\nDate:   Tue Nov 24 11:41:49 2009 -0500\n\n    hello world\n\ndiff --git a/foo b/foo\nnew file mode 100644\nindex 0000000..c1857fa\n--- /dev/null\n+++ b/foo\n@@ -0,0 +1 @@\n+Tue Nov 24 11:41:49 EST 2009\n"},{"id":"128304","messageId":"4B0D291D.4060100@drmicha.warpmail.net","threadId":"21737","inReplyTo":"117f2cc80911240856lbbb923buc7d0407bc2cba6a9@mail.gmail.com","subject":"Re: insecurity in verify-tag?","fromName":"Michael J Gruber","fromEmail":"git@drmicha.warpmail.net","sentAt":"2009-11-25T12:54:53Z","receivedAt":"2009-11-25T12:54:53Z","isPatch":false,"sender":{"key":"git@grubix.eu","avatar":"https://avatars.githubusercontent.com/u/233215?v=4"},"body":"David Roundy venit, vidit, dixit 24.11.2009 17:56:\n> I've just been looking at the code and I see what looks like a (minor)\n> security hole in the verify-tag feature.  In particular, the tag\n> verification code doesn't check that the tag is signed by the same\n> user that created the tag.  To be fair, gpg does output the identity\n> of the key that created the signature as well as the key used to\n> create the signature, so an astute user could detect that some\n> shenanigans is going on.\n> \n> An attack would simply require getting one's own public key into the\n> keyring of a user.  This probably wouldn't be very easy at the moment,\n> but if people were to actually use encrypted email (and if they set\n> their mail agents to download public keys), it might require no more\n> then sending a signed email to a mailing list.\n> \n> Of course, you'd also somehow have to trick them into pulling (or\n> cloning) your corrupt tag, which probably requires compromising a\n> server (or mirror) somewhere.  But of course, the whole point of\n> signing tags is to eliminate precisely this danger.\n> \n> What should be done about this? First, there ought to be a feature to\n> limit git verify-tag to use a specific keyring.  Maybe there is an\n> environment variable, and it's just not documented in the man page?\n> \n> It would also seem like a good idea to at a minimum check that the\n> name/email associated with the signature is the same as that of the\n> tagger.  This doesn't gain you *too* much, since an attacker can\n> always create his own key with any name and email he likes, but at\n> least it means that users could feel safe adding keys to their public\n> keyring, as long as those keys have reasonable names/emails associated\n> with them, and as long as they run git show on a tag before trusting\n> that that tag came from a particular person.  i.e. it seems reasonable\n> for me to expect that if I run:\n> \n> $ git show v1.0\n> tag v1.0\n> Tagger: Linus Torvalds ...\n> ...\n> [user carefully reads the Tagger line...]\n> $ git verify-tag v1.0 && make\n> \n> That I won't be running make on a repository that wasn't signed by a\n> key that at least *claims* to belong to Linus Torvalds.\n> \n> Thoughts?\n\nMy thought is that this is the wrong way to deal with signatures, be it\nsignatures on tags or signatures on other documents such as e-mails.\n\nEveryone can produce a valid signature. Everyone can set an arbitrary\ntagger name or commit author. They are meaningless. A \"Tagger\" really is\nthe committer of a tag object, whereas the signer is the actual author\nof the signature.\n\nThe only case where a signature bears any value is when\n\n- the signature is valid (in the sense of formal validity)\nAND\n- you trust the signer (i.e. the person and the key).\n\nSpecifically, you are supposed NOT to go by the return code of gpg\n--verify (which is behind verify-tag). It doesn't mean all that much. On\na side note, that was an attack vector on gpg users last year or so.\n\nAll that git itself could do is compare the tagger and the signer, and\nwarn you if they differ, that is: the signer's key contains no uid\nmatching the tagger. But this piece of information is really orthogonal\nto the issue of trustworthiness.\n\nNote that the actual signature verification process depends also on the\ngpg trust model (pgp/classic/...) that you're using and your trustdb. If\nyou want to use a specific gpg setup or keyring for tag purposes you can\ndo something like\n\nGNUPGHOME=~/.gpgforgit git verify-tag v1.6.5\n\nMichael\n"}]}