{"thread":{"id":"53664","subject":"Question: Setting the Email Address in ~/.gitconfig","startedAt":"2020-06-11T21:26:26Z","lastAt":"2020-06-13T00:25:18Z","messageCount":3,"participants":["Shreya Malviya","brian m. carlson","Aaron Schrab"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"399566","messageId":"CAEqpqjGNANrCX0wMDUP+dZ+_PdMveSJf6XFyiCpJdUH5t6jXvw@mail.gmail.com","threadId":"53664","inReplyTo":null,"subject":"Question: Setting the Email Address in ~/.gitconfig","fromName":"Shreya Malviya","fromEmail":"shreya.malviya@gmail.com","sentAt":"2020-06-11T21:25:45Z","receivedAt":"2020-06-11T21:26:26Z","isPatch":false,"sender":{"key":"shreya.malviya@gmail.com","avatar":null},"body":"Hi!\n\n\nI was playing around with git when I realized that it's possible for\nme to commit something to a repository as another user (explained a\nscenario below for a better understanding of what I mean) and it is\nnot considered a security vulnerability, understandably so\n(https://bounty.github.com/ineligible.html#impersonating_a_user_through_git_email_address).\n\nFor example, let's assume I have push access to some repository called\nAAA, and my email address is abc@xyz.com. I can simply edit\n~/.gitconfig on my system and set the email address as some other\nperson's email address: def@pqr.com. Then, I make some changes in my\nlocal repository and commit them (reminder: it's with the email\naddress def@pqr.com since git tracks commits by email address). Now,\nif I try to push to the remote repository, it asks for the username\nand password. I put mine and since I have push access to AAA, it goes\nthrough. I've successfully pushed commits on behalf of the owner of\nthe email address: def@pqr.com.\n\nSo basically, in this way, I can impersonate people and add commits on\ntheir behalf. BUT AGAIN, this is not considered a vulnerability (link\nfor reason attached before).\n\nMy question:\nIt would be much easier if git didn't allow changing the email address\nso easily. Why hasn't git implemented OAuth, or something of that\nsort, for every time that the email address is changed in\n~/.gitconfig, yet?\n\n\nShreya Malviya\n"},{"id":"399567","messageId":"20200611225216.GZ6569@camp.crustytoothpaste.net","threadId":"53664","inReplyTo":"CAEqpqjGNANrCX0wMDUP+dZ+_PdMveSJf6XFyiCpJdUH5t6jXvw@mail.gmail.com","subject":"Re: Question: Setting the Email Address in ~/.gitconfig","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2020-06-11T22:52:31Z","receivedAt":"2020-06-11T22:53:09Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2020-06-11 at 21:25:45, Shreya Malviya wrote:\n> Hi!\n> \n> \n> I was playing around with git when I realized that it's possible for\n> me to commit something to a repository as another user (explained a\n> scenario below for a better understanding of what I mean) and it is\n> not considered a security vulnerability, understandably so\n> (https://bounty.github.com/ineligible.html#impersonating_a_user_through_git_email_address).\n\nThis is GitHub's bug bounty policy, not Git's, but it is definitely an\nintended feature in Git and not a bug.  I should point out that they are\nseparate and independent.\n\n> For example, let's assume I have push access to some repository called\n> AAA, and my email address is abc@xyz.com. I can simply edit\n> ~/.gitconfig on my system and set the email address as some other\n> person's email address: def@pqr.com. Then, I make some changes in my\n> local repository and commit them (reminder: it's with the email\n> address def@pqr.com since git tracks commits by email address). Now,\n> if I try to push to the remote repository, it asks for the username\n> and password. I put mine and since I have push access to AAA, it goes\n> through. I've successfully pushed commits on behalf of the owner of\n> the email address: def@pqr.com.\n> \n> So basically, in this way, I can impersonate people and add commits on\n> their behalf. BUT AGAIN, this is not considered a vulnerability (link\n> for reason attached before).\n\nIn the Git project, users send patches to a mailing list and those\npatches are applied by a maintainer.  When the maintainer applies them,\nthey contain the user's identification and therefore are attributed to\nthat user as the author.  This is a common workflow in patch-based\nprojects.\n\nDisallowing people from pushing commits that contain another email\naddress would prevent the maintainer from pushing commits authored by\nothers, so Git doesn't do that, although it can be configured with push\ncertificates and a hook if you like.\n\nIf you are asking why GitHub attributes commits based on email, you'd\nhave to ask them.  However, be aware that there are projects that are\nconcerned about commit spoofing, especially corporate projects in\nregulated industries, and the way to handle that is to use and require\ncommit signing.\n\n> My question:\n> It would be much easier if git didn't allow changing the email address\n> so easily. Why hasn't git implemented OAuth, or something of that\n> sort, for every time that the email address is changed in\n> ~/.gitconfig, yet?\n\nThis is a local configuration file, so asking someone to implement OAuth\nto change a local configuration file wouldn't be helpful.  Many Git\nservers are, for example, SSH only, and so OAuth isn't even a\npossibility.\n-- \nbrian m. carlson: Houston, Texas, US\nOpenPGP: https://keybase.io/bk2204\n"},{"id":"399636","messageId":"20200613001654.GA190001@pug.qqx.org","threadId":"53664","inReplyTo":"20200611225216.GZ6569@camp.crustytoothpaste.net","subject":"Re: Question: Setting the Email Address in ~/.gitconfig","fromName":"Aaron Schrab","fromEmail":"aaron@schrab.com","sentAt":"2020-06-13T00:16:54Z","receivedAt":"2020-06-13T00:25:18Z","isPatch":false,"sender":{"key":"aaron@schrab.com","avatar":"https://avatars.githubusercontent.com/u/39620?v=4"},"body":"At 22:52 +0000 11 Jun 2020, \"brian m. carlson\" <sandals@crustytoothpaste.net> wrote:\n>On 2020-06-11 at 21:25:45, Shreya Malviya wrote:\n>> My question:\n>> It would be much easier if git didn't allow changing the email address\n>> so easily. Why hasn't git implemented OAuth, or something of that\n>> sort, for every time that the email address is changed in\n>> ~/.gitconfig, yet?\n>\n>This is a local configuration file, so asking someone to implement OAuth\n>to change a local configuration file wouldn't be helpful.  Many Git\n>servers are, for example, SSH only, and so OAuth isn't even a\n>possibility.\n\nBeyond that, even if git *did* somehow provide strong authentication of \nthe configured email address for commits, it's open source software so \npeople could still quite easily disable that authentication to spoof \ncommits as other people. They could also use some other software \n(possibly that they write themselves) that manipulates a repository \nwithout doing that authentication.\n\nWhile the data is entirely on an untrusted system (however you want to \ndefine trusted), the operator of that system will always be able to \nmanipulate that data.\n\nThe alternative to this would be to require all commits to be \ncryptographically signed. But, most projects consider that to be too \nmuch of a burden. After all that only covers who made the changes, while \nfor many things the content of the changes is much more important.\n"}]}