git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Transparently encrypt repository contents with GPG

From
lalebarde <l.alebarde@free.fr>
Date
Jun 17, 2012, 07:33 UTC
Message-ID
<1339918412381-7561644.post@n2.nabble.com>
In-Reply-To
<1335029110871-7487506.post@n2.nabble.com>

Hi, I am puzzled from the http://article.gmane.org/gmane.comp.version-control.git/113221 recommandation of Junio C Hamano , the maintainer of git, to not encrypt files before pushing them :

Junio C Hamano wrote
> If your "clean" encrypts and "smudge" decrypts, it means you are refusing
> all the benifit git offers.
Junio C Hamano wrote
> the above config may appear to work

*So, does it work or not, or partially ? And if partially, what does not work ?*

Another issue is the use of the cypher ECB by https://github.com/shadowhand/git-encrypt git-encrypt . http://stackoverflow.com/questions/1220751/how-to-choose-an-aes-encryption-mode-cbc-ecb-ctr-ocb-cfb Some argue it is bad (cf also http://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Electronic_codebook_.28ECB.29 that ).

So I made some experiments, tacking a 15Mb pdf :

/$ openssl enc -base64 -aes-256-ecb -S 1762851 -k a5G4juy64VVBgfq4 <Wiley.pdf >WileyE1 $ openssl enc -base64 -aes-256-ecb -S 1762851 -k a5G4juy64VVBgfq4 <Wiley.pdf

>WileyE2

$ md5sum WileyE1 d43058d8443777aea871350245d9865b WileyE1 $ md5sum WileyE2 d43058d8443777aea871350245d9865b WileyE2

$ openssl enc -base64 -aes-256-ofb -S 1762851 -k a5G4juy64VVBgfq4 <Wiley.pdf
>WileyE1
$ openssl enc -base64 -aes-256-ofb -S 1762851 -k a5G4juy64VVBgfq4 <Wiley.pdf
>WileyE2

503d82849ad53652268d1abdcfbce9de WileyE1 503d82849ad53652268d1abdcfbce9de WileyE2

$ openssl enc -base64 -aes-256-cbc -S 1762851 -k a5G4juy64VVBgfq4 <Wiley.pdf
>WileyE1
$ openssl enc -base64 -aes-256-cbc -S 1762851 -k a5G4juy64VVBgfq4 <Wiley.pdf
>WileyE2

e726431cbd9ff8780946ddfad775600a WileyE1 e726431cbd9ff8780946ddfad775600a WileyE2/

*As the hash are identical from one run to another, I don't understand why we should stick to the ECB cypher.*

Can some one clarify the two points please ?

-- View this message in context: http://git.661346.n2.nabble.com/Transparently-encrypt-repository-contents-with-GPG-tp2470145p7561644.html Sent from the git mailing list archive at Nabble.com.

Previous: bigbearNext: lalebarde
Message 17 of 18 in “Transparently encrypt repository contents with GPG”
  1. Matthias NothhaftMar 12, 2009
  2. Sverre RabbelierMar 12, 2009
  3. Michael J GruberMar 13, 2009
  4. Sverre RabbelierMar 13, 2009
  5. Thomas RastMar 13, 2009
  6. Sverre RabbelierMar 13, 2009
  7. Michael J GruberMar 13, 2009
  8. Sverre RabbelierMar 13, 2009
  9. Jeff KingMar 13, 2009
  10. Junio C HamanoMar 13, 2009
  11. Michael J GruberMar 14, 2009
  12. Junio C HamanoMar 14, 2009
  13. Michael J GruberMar 16, 2009
  14. Jeff KingMar 17, 2009
  15. Jeff KingMar 17, 2009
  16. bigbearApr 21, 2012
  17. lalebardeJun 17, 2012
  18. lalebardeJun 18, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.