git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Commit signing

From
Karl Hasselström <kha@treskal.com>
Date
Jan 15, 2007, 14:52 UTC
Message-ID
<20070115145235.GA1830@diana.vm.bytemark.co.uk>
In-Reply-To
<20070115104336.GD12257@spearce.org>
On 2007-01-15 05:43:36 -0500, Shawn O. Pearce wrote:
Show 11 quoted lines
> If you don't trust the owner, but you trust the pusher, than using 1
> annotated tag per push is reasonable and gives you something to
> verify the repository owner isn't playing games. If you don't trust
> the pusher than you should be reviewing the changes before deciding
> to keep them in your project.
>
> But even then annotated tags are overkill. You could just receive
> the commit SHA1 out-of-band from the pusher (e.g. email, like
> Junio's hidden X-master-at header) and verify that by hand. 8 digits
> is probably more than enough to hand-verify the entire commit chain
> you are receiving.

No. You've just constructed a system whose security depends on a 32-bit hash. This is one of those situations where you really do need all the digits.

-- 
Karl Hasselström, kha@treskal.com
      www.treskal.com/kalle
Previous: Shawn O. PearceNext: Andy Parkins
Message 9 of 21 in “Commit signing”
  1. Andy ParkinsJan 15, 2007
  2. Matthias KestenholzJan 15, 2007
  3. Shawn O. PearceJan 15, 2007
  4. Shawn O. PearceJan 15, 2007
  5. Johannes SchindelinJan 15, 2007
  6. Daniel BarkalowJan 15, 2007
  7. Johannes SchindelinJan 15, 2007
  8. Shawn O. PearceJan 15, 2007
  9. Karl HasselströmJan 15, 2007
  10. Andy ParkinsJan 15, 2007
  11. Shawn O. PearceJan 15, 2007
  12. Johannes SchindelinJan 15, 2007
  13. Andy ParkinsJan 15, 2007
  14. Johannes SchindelinJan 15, 2007
  15. Andy ParkinsJan 15, 2007
  16. Martin LanghoffJan 15, 2007
  17. Andy ParkinsJan 15, 2007
  18. Martin LanghoffJan 15, 2007
  19. Johannes SchindelinJan 15, 2007
  20. Jakub NarebskiJan 15, 2007
  21. Jeff KingJan 15, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.