{"thread":{"id":"39710","subject":"Repository Code Security (Plan Text)","startedAt":"2015-06-24T18:18:00Z","lastAt":"2015-06-24T20:17:00Z","messageCount":9,"participants":["BGaudreault Brian","Konstantin Khomoutov","David Lang","David Turner"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"264745","messageId":"BLUPR0701MB19693B73E05DF433C6B70182D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","threadId":"39710","inReplyTo":null,"subject":"Repository Code Security (Plan Text)","fromName":"BGaudreault Brian","fromEmail":"bgaudreault@edrnet.com","sentAt":"2015-06-24T18:18:00Z","receivedAt":"2015-06-24T18:18:00Z","isPatch":false,"sender":{"key":"bgaudreault@edrnet.com","avatar":null},"body":"Hello,\n\nIf someone downloads code to their notebook PC and leaves the company, what protection do we have against them not being able to access the local code copy anymore?\n\nThanks,\nBrian\n"},{"id":"264747","messageId":"20150624213111.61ce6933040bbb7220d5903c@domain007.com","threadId":"39710","inReplyTo":"BLUPR0701MB19693B73E05DF433C6B70182D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","subject":"Re: Repository Code Security (Plan Text)","fromName":"Konstantin Khomoutov","fromEmail":"kostix+git@007spb.ru","sentAt":"2015-06-24T18:31:11Z","receivedAt":"2015-06-24T18:31:11Z","isPatch":false,"sender":{"key":"kostix+git@007spb.ru","avatar":null},"body":"On Wed, 24 Jun 2015 18:18:00 +0000\nBGaudreault Brian <BGaudreault@edrnet.com> wrote:\n\n> If someone downloads code to their notebook PC and leaves the\n> company, what protection do we have against them not being able to\n> access the local code copy anymore?\n\nWhat do you mean by \"local code\"?\nThat one which is on the notebook?\nThen you can do literally nothing except for not allowing cloning your\nGit repositories onto random computers in the first place.\n\nIf you instead mean the copy of code available in the repositories\nhosted in your enterprise then all you need to do is to somehow\nterminate the access of that employee who's left to those repositories.\n(This assumes they're accessible from the outside; if they aren't, the\nproblem simply do not exist.)\n"},{"id":"264750","messageId":"BLUPR0701MB196947C0396E91F8CCE39200D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","threadId":"39710","inReplyTo":"20150624213111.61ce6933040bbb7220d5903c@domain007.com","subject":"RE: Repository Code Security (Plan Text)","fromName":"BGaudreault Brian","fromEmail":"bgaudreault@edrnet.com","sentAt":"2015-06-24T18:59:45Z","receivedAt":"2015-06-24T18:59:45Z","isPatch":false,"sender":{"key":"bgaudreault@edrnet.com","avatar":null},"body":"Thanks.  Yes, I meant that \"local code\" is code pulled down to a person's PC, so we don't want them to leave the company with access to this code.  So we can only prevent this scenario by running GitLab in our environment instead of running GitHub in the cloud?  Would removing a GitHub account from the GitHub repository prevent them from accessing the code on their PC?\n\nHow do you prevent private GitHub repositories from being pulled down to unauthorized PCs?\n\nThanks,\nBrian\n\n-----Original Message-----\nFrom: Konstantin Khomoutov [mailto:kostix+git@007spb.ru] \nSent: Wednesday, June 24, 2015 2:31 PM\nTo: BGaudreault Brian\nCc: git@vger.kernel.org\nSubject: Re: Repository Code Security (Plan Text)\n\nOn Wed, 24 Jun 2015 18:18:00 +0000\nBGaudreault Brian <BGaudreault@edrnet.com> wrote:\n\n> If someone downloads code to their notebook PC and leaves the company, \n> what protection do we have against them not being able to access the \n> local code copy anymore?\n\nWhat do you mean by \"local code\"?\nThat one which is on the notebook?\nThen you can do literally nothing except for not allowing cloning your Git repositories onto random computers in the first place.\n\nIf you instead mean the copy of code available in the repositories hosted in your enterprise then all you need to do is to somehow terminate the access of that employee who's left to those repositories.\n(This assumes they're accessible from the outside; if they aren't, the problem simply do not exist.)\n"},{"id":"264759","messageId":"alpine.DEB.2.02.1506241217010.4148@nftneq.ynat.uz","threadId":"39710","inReplyTo":"BLUPR0701MB196947C0396E91F8CCE39200D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","subject":"RE: Repository Code Security (Plan Text)","fromName":"David Lang","fromEmail":"david@lang.hm","sentAt":"2015-06-24T19:20:26Z","receivedAt":"2015-06-24T19:20:26Z","isPatch":false,"sender":{"key":"david@lang.hm","avatar":null},"body":"On Wed, 24 Jun 2015, BGaudreault Brian wrote:\n\n> Thanks.  Yes, I meant that \"local code\" is code pulled down to a person's PC, so we don't want them to leave the company with access to this code.  So we can only prevent this scenario by running GitLab in our environment instead of running GitHub in the cloud?  Would removing a GitHub account from the GitHub repository prevent them from accessing the code on their PC?\n>\n> How do you prevent private GitHub repositories from being pulled down to unauthorized PCs?\n\npolicy, you say that it's against policy for someone to put company info on a \npersonal machine.\n\nYou probably run your own repository that's only available within your network \n(or over your VPN) rather than using a cloud service like github (you may want \nto check with github to see if they can lock down a private repo to only be \naccessed from specific IP addresses)\n\nyou will also need to make sure that people don't plug personal laptops into \nyour corporate network, and that they don't use personal phones to access \ncompany e-mail.\n\nThe bottom line is that it's no different from preventing them from having \naccess to any other sensitive data in your company. What measures do you have in \nplace to keep them from taking sensitive Word Docs or spreadsheets when they \nleave? do the same thing to deal with their access to code.\n\nDavid Lang\n\n> Thanks,\n> Brian\n>\n> -----Original Message-----\n>\n> On Wed, 24 Jun 2015 18:18:00 +0000\n> BGaudreault Brian <BGaudreault@edrnet.com> wrote:\n>\n>> If someone downloads code to their notebook PC and leaves the company,\n>> what protection do we have against them not being able to access the\n>> local code copy anymore?\n>\n> What do you mean by \"local code\"?\n> That one which is on the notebook?\n> Then you can do literally nothing except for not allowing cloning your Git repositories onto random computers in the first place.\n>\n> If you instead mean the copy of code available in the repositories hosted in your enterprise then all you need to do is to somehow terminate the access of that employee who's left to those repositories.\n> (This assumes they're accessible from the outside; if they aren't, the problem simply do not exist.)\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n>\n"},{"id":"264760","messageId":"1435173672.6499.2.camel@twopensource.com","threadId":"39710","inReplyTo":"BLUPR0701MB196947C0396E91F8CCE39200D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","subject":"Re: Repository Code Security (Plan Text)","fromName":"David Turner","fromEmail":"dturner@twopensource.com","sentAt":"2015-06-24T19:21:12Z","receivedAt":"2015-06-24T19:21:12Z","isPatch":false,"sender":{"key":"novalis@novalis.org","avatar":"https://avatars.githubusercontent.com/u/77003?v=4"},"body":"What most companies do is this: they issue their employees computers,\nand then when the employee leaves, they take the computers away.  Of\ncourse, someone could have copied the code before leaving the company.\nThe typical remedy for this is a contract saying \"don't do that\".  But I\nguess some companies just go straight to the FBI see e.g.:\nhttps://en.wikipedia.org/wiki/Sergey_Aleynikov\n\nThere is no technological solution that will prevent someone from\naccessing something that lives on their own computer (just ask the movie\nand music industries, which tried to find one for about twenty years).  \n\nOn Wed, 2015-06-24 at 18:59 +0000, BGaudreault Brian wrote:\n> Thanks.  Yes, I meant that \"local code\" is code pulled down to a person's PC, so we don't want them to leave the company with access to this code.  So we can only prevent this scenario by running GitLab in our environment instead of running GitHub in the cloud?  Would removing a GitHub account from the GitHub repository prevent them from accessing the code on their PC?\n> \n> How do you prevent private GitHub repositories from being pulled down to unauthorized PCs?\n> \n> Thanks,\n> Brian\n> \n> -----Original Message-----\n> From: Konstantin Khomoutov [mailto:kostix+git@007spb.ru] \n> Sent: Wednesday, June 24, 2015 2:31 PM\n> To: BGaudreault Brian\n> Cc: git@vger.kernel.org\n> Subject: Re: Repository Code Security (Plan Text)\n> \n> On Wed, 24 Jun 2015 18:18:00 +0000\n> BGaudreault Brian <BGaudreault@edrnet.com> wrote:\n> \n> > If someone downloads code to their notebook PC and leaves the company, \n> > what protection do we have against them not being able to access the \n> > local code copy anymore?\n> \n> What do you mean by \"local code\"?\n> That one which is on the notebook?\n> Then you can do literally nothing except for not allowing cloning your Git repositories onto random computers in the first place.\n> \n> If you instead mean the copy of code available in the repositories hosted in your enterprise then all you need to do is to somehow terminate the access of that employee who's left to those repositories.\n> (This assumes they're accessible from the outside; if they aren't, the problem simply do not exist.)\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n"},{"id":"264763","messageId":"BLUPR0701MB1969E8CB9B348504F02231F3D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","threadId":"39710","inReplyTo":"alpine.DEB.2.02.1506241217010.4148@nftneq.ynat.uz","subject":"RE: Repository Code Security (Plan Text)","fromName":"BGaudreault Brian","fromEmail":"bgaudreault@edrnet.com","sentAt":"2015-06-24T19:53:23Z","receivedAt":"2015-06-24T19:53:23Z","isPatch":false,"sender":{"key":"bgaudreault@edrnet.com","avatar":null},"body":"Hi David Lang,\n\nI'm sorry, but I'm confused by your first two responses.  Am I not contacting Git when I e-mail this e-mail address?  You sound like you don't know exactly how GitHub works.  Should I be contacting someone else for GitHub support?\n\nThanks,\nBrian\n\n-----Original Message-----\nFrom: David Lang [mailto:david@lang.hm] \nSent: Wednesday, June 24, 2015 3:20 PM\nTo: BGaudreault Brian\nCc: Konstantin Khomoutov; git@vger.kernel.org\nSubject: RE: Repository Code Security (Plan Text)\n\nOn Wed, 24 Jun 2015, BGaudreault Brian wrote:\n\n> Thanks.  Yes, I meant that \"local code\" is code pulled down to a person's PC, so we don't want them to leave the company with access to this code.  So we can only prevent this scenario by running GitLab in our environment instead of running GitHub in the cloud?  Would removing a GitHub account from the GitHub repository prevent them from accessing the code on their PC?\n>\n> How do you prevent private GitHub repositories from being pulled down to unauthorized PCs?\n\npolicy, you say that it's against policy for someone to put company info on a personal machine.\n\nYou probably run your own repository that's only available within your network (or over your VPN) rather than using a cloud service like github (you may want to check with github to see if they can lock down a private repo to only be accessed from specific IP addresses)\n\nyou will also need to make sure that people don't plug personal laptops into your corporate network, and that they don't use personal phones to access company e-mail.\n\nThe bottom line is that it's no different from preventing them from having access to any other sensitive data in your company. What measures do you have in place to keep them from taking sensitive Word Docs or spreadsheets when they leave? do the same thing to deal with their access to code.\n\nDavid Lang\n\n> Thanks,\n> Brian\n>\n> -----Original Message-----\n>\n> On Wed, 24 Jun 2015 18:18:00 +0000\n> BGaudreault Brian <BGaudreault@edrnet.com> wrote:\n>\n>> If someone downloads code to their notebook PC and leaves the \n>> company, what protection do we have against them not being able to \n>> access the local code copy anymore?\n>\n> What do you mean by \"local code\"?\n> That one which is on the notebook?\n> Then you can do literally nothing except for not allowing cloning your Git repositories onto random computers in the first place.\n>\n> If you instead mean the copy of code available in the repositories hosted in your enterprise then all you need to do is to somehow terminate the access of that employee who's left to those repositories.\n> (This assumes they're accessible from the outside; if they aren't, the \n> problem simply do not exist.)\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in the \n> body of a message to majordomo@vger.kernel.org More majordomo info at  \n> http://vger.kernel.org/majordomo-info.html\n>\n"},{"id":"264775","messageId":"1435176014.6499.4.camel@twopensource.com","threadId":"39710","inReplyTo":"BLUPR0701MB1969E8CB9B348504F02231F3D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","subject":"Re: Repository Code Security (Plan Text)","fromName":"David Turner","fromEmail":"dturner@twopensource.com","sentAt":"2015-06-24T20:00:14Z","receivedAt":"2015-06-24T20:00:14Z","isPatch":false,"sender":{"key":"novalis@novalis.org","avatar":"https://avatars.githubusercontent.com/u/77003?v=4"},"body":"Git is not GitHub (any more than a cat is a cathouse).  Git is a piece\nof software; GitHub is a hosting service for Git.  Contact GitHub for\nGitHub support.\n\n\nOn Wed, 2015-06-24 at 19:53 +0000, BGaudreault Brian wrote:\n> Hi David Lang,\n> \n> I'm sorry, but I'm confused by your first two responses.  Am I not contacting Git when I e-mail this e-mail address?  You sound like you don't know exactly how GitHub works.  Should I be contacting someone else for GitHub support?\n> \n> Thanks,\n> Brian\n> \n> -----Original Message-----\n> From: David Lang [mailto:david@lang.hm] \n> Sent: Wednesday, June 24, 2015 3:20 PM\n> To: BGaudreault Brian\n> Cc: Konstantin Khomoutov; git@vger.kernel.org\n> Subject: RE: Repository Code Security (Plan Text)\n> \n> On Wed, 24 Jun 2015, BGaudreault Brian wrote:\n> \n> > Thanks.  Yes, I meant that \"local code\" is code pulled down to a person's PC, so we don't want them to leave the company with access to this code.  So we can only prevent this scenario by running GitLab in our environment instead of running GitHub in the cloud?  Would removing a GitHub account from the GitHub repository prevent them from accessing the code on their PC?\n> >\n> > How do you prevent private GitHub repositories from being pulled down to unauthorized PCs?\n> \n> policy, you say that it's against policy for someone to put company info on a personal machine.\n> \n> You probably run your own repository that's only available within your network (or over your VPN) rather than using a cloud service like github (you may want to check with github to see if they can lock down a private repo to only be accessed from specific IP addresses)\n> \n> you will also need to make sure that people don't plug personal laptops into your corporate network, and that they don't use personal phones to access company e-mail.\n> \n> The bottom line is that it's no different from preventing them from having access to any other sensitive data in your company. What measures do you have in place to keep them from taking sensitive Word Docs or spreadsheets when they leave? do the same thing to deal with their access to code.\n> \n> David Lang\n> \n> > Thanks,\n> > Brian\n> >\n> > -----Original Message-----\n> >\n> > On Wed, 24 Jun 2015 18:18:00 +0000\n> > BGaudreault Brian <BGaudreault@edrnet.com> wrote:\n> >\n> >> If someone downloads code to their notebook PC and leaves the \n> >> company, what protection do we have against them not being able to \n> >> access the local code copy anymore?\n> >\n> > What do you mean by \"local code\"?\n> > That one which is on the notebook?\n> > Then you can do literally nothing except for not allowing cloning your Git repositories onto random computers in the first place.\n> >\n> > If you instead mean the copy of code available in the repositories hosted in your enterprise then all you need to do is to somehow terminate the access of that employee who's left to those repositories.\n> > (This assumes they're accessible from the outside; if they aren't, the \n> > problem simply do not exist.)\n> > --\n> > To unsubscribe from this list: send the line \"unsubscribe git\" in the \n> > body of a message to majordomo@vger.kernel.org More majordomo info at  \n> > http://vger.kernel.org/majordomo-info.html\n> >\n"},{"id":"264776","messageId":"alpine.DEB.2.02.1506241308140.4148@nftneq.ynat.uz","threadId":"39710","inReplyTo":"BLUPR0701MB1969E8CB9B348504F02231F3D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","subject":"RE: Repository Code Security (Plan Text)","fromName":"David Lang","fromEmail":"david@lang.hm","sentAt":"2015-06-24T20:10:49Z","receivedAt":"2015-06-24T20:10:49Z","isPatch":false,"sender":{"key":"david@lang.hm","avatar":null},"body":"On Wed, 24 Jun 2015, BGaudreault Brian wrote:\n\n> Hi David Lang,\n>\n> I'm sorry, but I'm confused by your first two responses.  Am I not contacting \n> Git when I e-mail this e-mail address?  You sound like you don't know exactly \n> how GitHub works.  Should I be contacting someone else for GitHub support?\n\ngit is the opensource distributed version control software that github uses as \npart of their offering. This is the mailing list used by the developers of git. \nVery few of the developers here work for github.\n\nFor github support, you will need to contact the company github.\n\nDavid Lang\n\n> Thanks,\n> Brian\n>\n> -----Original Message-----\n> From: David Lang [mailto:david@lang.hm]\n> Sent: Wednesday, June 24, 2015 3:20 PM\n> To: BGaudreault Brian\n> Cc: Konstantin Khomoutov; git@vger.kernel.org\n> Subject: RE: Repository Code Security (Plan Text)\n>\n> On Wed, 24 Jun 2015, BGaudreault Brian wrote:\n>\n>> Thanks.  Yes, I meant that \"local code\" is code pulled down to a person's PC, so we don't want them to leave the company with access to this code.  So we can only prevent this scenario by running GitLab in our environment instead of running GitHub in the cloud?  Would removing a GitHub account from the GitHub repository prevent them from accessing the code on their PC?\n>>\n>> How do you prevent private GitHub repositories from being pulled down to unauthorized PCs?\n>\n> policy, you say that it's against policy for someone to put company info on a personal machine.\n>\n> You probably run your own repository that's only available within your network (or over your VPN) rather than using a cloud service like github (you may want to check with github to see if they can lock down a private repo to only be accessed from specific IP addresses)\n>\n> you will also need to make sure that people don't plug personal laptops into your corporate network, and that they don't use personal phones to access company e-mail.\n>\n> The bottom line is that it's no different from preventing them from having access to any other sensitive data in your company. What measures do you have in place to keep them from taking sensitive Word Docs or spreadsheets when they leave? do the same thing to deal with their access to code.\n>\n> David Lang\n>\n>> Thanks,\n>> Brian\n>>\n>> -----Original Message-----\n>>\n>> On Wed, 24 Jun 2015 18:18:00 +0000\n>> BGaudreault Brian <BGaudreault@edrnet.com> wrote:\n>>\n>>> If someone downloads code to their notebook PC and leaves the\n>>> company, what protection do we have against them not being able to\n>>> access the local code copy anymore?\n>>\n>> What do you mean by \"local code\"?\n>> That one which is on the notebook?\n>> Then you can do literally nothing except for not allowing cloning your Git repositories onto random computers in the first place.\n>>\n>> If you instead mean the copy of code available in the repositories hosted in your enterprise then all you need to do is to somehow terminate the access of that employee who's left to those repositories.\n>> (This assumes they're accessible from the outside; if they aren't, the\n>> problem simply do not exist.)\n>> --\n>> To unsubscribe from this list: send the line \"unsubscribe git\" in the\n>> body of a message to majordomo@vger.kernel.org More majordomo info at\n>> http://vger.kernel.org/majordomo-info.html\n>>\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n>\n"},{"id":"264777","messageId":"BLUPR0701MB19695641DC72D62EC246EDF3D7AF0@BLUPR0701MB1969.namprd07.prod.outlook.com","threadId":"39710","inReplyTo":"1435176014.6499.4.camel@twopensource.com","subject":"RE: Repository Code Security (Plan Text)","fromName":"BGaudreault Brian","fromEmail":"bgaudreault@edrnet.com","sentAt":"2015-06-24T20:17:00Z","receivedAt":"2015-06-24T20:17:00Z","isPatch":false,"sender":{"key":"bgaudreault@edrnet.com","avatar":null},"body":"Ok, thanks.  I didn't realize there was a difference!  I thought Git SCM ran GitHub.  I haven't yet read this clear distinction.  Of course I wasn't the one who chose GitHub in the first place.\n\n-----Original Message-----\nFrom: David Turner [mailto:dturner@twopensource.com] \nSent: Wednesday, June 24, 2015 4:00 PM\nTo: BGaudreault Brian\nCc: David Lang; Konstantin Khomoutov; git@vger.kernel.org\nSubject: Re: Repository Code Security (Plan Text)\n\nGit is not GitHub (any more than a cat is a cathouse).  Git is a piece of software; GitHub is a hosting service for Git.  Contact GitHub for GitHub support.\n\n\nOn Wed, 2015-06-24 at 19:53 +0000, BGaudreault Brian wrote:\n> Hi David Lang,\n> \n> I'm sorry, but I'm confused by your first two responses.  Am I not contacting Git when I e-mail this e-mail address?  You sound like you don't know exactly how GitHub works.  Should I be contacting someone else for GitHub support?\n> \n> Thanks,\n> Brian\n> \n> -----Original Message-----\n> From: David Lang [mailto:david@lang.hm]\n> Sent: Wednesday, June 24, 2015 3:20 PM\n> To: BGaudreault Brian\n> Cc: Konstantin Khomoutov; git@vger.kernel.org\n> Subject: RE: Repository Code Security (Plan Text)\n> \n> On Wed, 24 Jun 2015, BGaudreault Brian wrote:\n> \n> > Thanks.  Yes, I meant that \"local code\" is code pulled down to a person's PC, so we don't want them to leave the company with access to this code.  So we can only prevent this scenario by running GitLab in our environment instead of running GitHub in the cloud?  Would removing a GitHub account from the GitHub repository prevent them from accessing the code on their PC?\n> >\n> > How do you prevent private GitHub repositories from being pulled down to unauthorized PCs?\n> \n> policy, you say that it's against policy for someone to put company info on a personal machine.\n> \n> You probably run your own repository that's only available within your \n> network (or over your VPN) rather than using a cloud service like \n> github (you may want to check with github to see if they can lock down \n> a private repo to only be accessed from specific IP addresses)\n> \n> you will also need to make sure that people don't plug personal laptops into your corporate network, and that they don't use personal phones to access company e-mail.\n> \n> The bottom line is that it's no different from preventing them from having access to any other sensitive data in your company. What measures do you have in place to keep them from taking sensitive Word Docs or spreadsheets when they leave? do the same thing to deal with their access to code.\n> \n> David Lang\n> \n> > Thanks,\n> > Brian\n> >\n> > -----Original Message-----\n> >\n> > On Wed, 24 Jun 2015 18:18:00 +0000\n> > BGaudreault Brian <BGaudreault@edrnet.com> wrote:\n> >\n> >> If someone downloads code to their notebook PC and leaves the \n> >> company, what protection do we have against them not being able to \n> >> access the local code copy anymore?\n> >\n> > What do you mean by \"local code\"?\n> > That one which is on the notebook?\n> > Then you can do literally nothing except for not allowing cloning your Git repositories onto random computers in the first place.\n> >\n> > If you instead mean the copy of code available in the repositories hosted in your enterprise then all you need to do is to somehow terminate the access of that employee who's left to those repositories.\n> > (This assumes they're accessible from the outside; if they aren't, \n> > the problem simply do not exist.)\n> > --\n> > To unsubscribe from this list: send the line \"unsubscribe git\" in \n> > the body of a message to majordomo@vger.kernel.org More majordomo \n> > info at http://vger.kernel.org/majordomo-info.html\n> >\n\n\n"}]}