git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Q] Encrypted GIT?

From
Jeff King <peff@peff.net>
Date
Mar 13, 2008, 16:00 UTC
Message-ID
<20080313160016.GB30847@coredump.intra.peff.net>
In-Reply-To
<alpine.LSU.1.00.0803131620270.1656@racer.site>
On Thu, Mar 13, 2008 at 04:21:44PM +0100, Johannes Schindelin wrote:
Show 5 quoted lines
> > No, and you wouldn't want to use gpg because of the overhead it adds
> > around an encrypted message.
> 
> To the contrary: if your files are small (which they are most likely), you 
> _want_ the overhead, in order to make the encryption harder to crack.

Not necessarily. Using random IVs, random salts, and random padding does increase security. Adding headers to every object that tell which algorithm and parameters were used are nice for interoperability, but don't help with security. Doing per-object asymmetric encryptions (gpg --encrypt without --symmetric) is performance insanity.

> AFAICT gpg is a good all-round encryption tool, and reinventing the wheel 
> just for encrypting things in a git repository just does not cut it.

Keep in mind that in the example you posted before, you were not using 99% of gpg. You were just asking it to do a symmetric CBC cipher using a passphrase. So it is overkill for that, but at the same time not actually very flexible for doing those sorts of low-level things. OpenSSL provides a much better toolkit for that.

-Peff
Previous: Johannes SchindelinNext: Jeff King
Message 8 of 17 in “[Q] Encrypted GIT?”
  1. Alexander GladyshMar 13, 2008
  2. Miklos VajnaMar 13, 2008
  3. Johannes SchindelinMar 13, 2008
  4. Miklos VajnaMar 13, 2008
  5. Theodore TsoMar 13, 2008
  6. Alexander GladyshMar 13, 2008
  7. Johannes SchindelinMar 13, 2008
  8. Jeff KingMar 13, 2008
  9. Jeff KingMar 13, 2008
  10. Jeff KingMar 13, 2008
  11. Theodore TsoMar 13, 2008
  12. Jeff KingMar 13, 2008
  13. David BrownMar 13, 2008
  14. Thomas HarningMar 13, 2008
  15. Luke LuMar 13, 2008
  16. Thomas HarningMar 13, 2008
  17. Luke LuMar 13, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.