git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Q] Encrypted GIT?

From
Theodore Tso <tytso@mit.edu>
Date
Mar 13, 2008, 16:12 UTC
Message-ID
<20080313161201.GA31653@mit.edu>
In-Reply-To
<20080313155322.GA30847@coredump.intra.peff.net>
On Thu, Mar 13, 2008 at 11:53:22AM -0400, Jeff King wrote:
Show 9 quoted lines
>   - encrypting whole packfiles is a bit better for transport. The
>     key-holding repo does the deltas and just treats the remote repo as
>     dumb storage (it can't be smart, since that would involve looking at
>     the data). Storage overhead is minimal if packfiles are a reasonable
>     size.
> 
> So I think the last makes the most sense, where your local repo is
> totally unprotected, but you efficiently push git objects to a remote
> untrusted repo.

If the main goal is primarily backup of your repository to an untrusted remote server, yes, that makes perfect sense.

If you assume multiple trusted developers would actually be *operating* on an encrypted repo, the life gets much harder, as you've pointed out.

>   - encrypting before git sees content sucks, because you are either
>     sacrificing security (content X always encrypts to Y) or system
>     stability (git doesn't know that Y and Y' are really the same thing)

It's not clear that "content X always encrypts to Y" is a fatal flaw, by the way. Yes, it leaks a bit of information, but in a source code management situation, it may not matter. If you do absolutely care, tough, it might be that the simplest solution is to store the entire repository and working tree under cryptofs. After all, what's the point of encrypting the local repo if the checked-out working tree is unprotected for all to see? :-)

						- Ted
Previous: Jeff KingNext: Jeff King
Message 11 of 17 in “[Q] Encrypted GIT?”
  1. Alexander GladyshMar 13, 2008
  2. Miklos VajnaMar 13, 2008
  3. Johannes SchindelinMar 13, 2008
  4. Miklos VajnaMar 13, 2008
  5. Theodore TsoMar 13, 2008
  6. Alexander GladyshMar 13, 2008
  7. Johannes SchindelinMar 13, 2008
  8. Jeff KingMar 13, 2008
  9. Jeff KingMar 13, 2008
  10. Jeff KingMar 13, 2008
  11. Theodore TsoMar 13, 2008
  12. Jeff KingMar 13, 2008
  13. David BrownMar 13, 2008
  14. Thomas HarningMar 13, 2008
  15. Luke LuMar 13, 2008
  16. Thomas HarningMar 13, 2008
  17. Luke LuMar 13, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.