git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Q] Encrypted GIT?

From
Jeff King <peff@peff.net>
Date
Mar 13, 2008, 16:19 UTC
Message-ID
<20080313161919.GA2050@coredump.intra.peff.net>
In-Reply-To
<20080313161201.GA31653@mit.edu>
On Thu, Mar 13, 2008 at 12:12:01PM -0400, Theodore Tso wrote:
Show 6 quoted lines
> If the main goal is primarily backup of your repository to an
> untrusted remote server, yes, that makes perfect sense.  
> 
> If you assume multiple trusted developers would actually be
> *operating* on an encrypted repo, the life gets much harder, as you've
> pointed out.

Well, it depends on the meaning of "operate". :) I think you could still use it as a rendezvous point as you would any bare repository. Pushing and pulling would have a little larger network overhead, and a lot more CPU overhead.

But yes, that scheme is horrible for a working repo.
Show 6 quoted lines
> >   - encrypting before git sees content sucks, because you are either
> >     sacrificing security (content X always encrypts to Y) or system
> >     stability (git doesn't know that Y and Y' are really the same thing)
> 
> It's not clear that "content X always encrypts to Y" is a fatal flaw,
> by the way.  Yes, it leaks a bit of information, but in a source code

Agreed (I actually recommended in Dscho's original thread "you can do it by eliminating the salt, if you accept the consequences...").

So after my saying "no formal threat analysis is necessary" you have clearly called me on making a bunch of usage assumptions. Oops. :)

Show 5 quoted lines
> management situation, it may not matter.  If you do absolutely care,
> tough, it might be that the simplest solution is to store the entire
> repository and working tree under cryptofs.  After all, what's the
> point of encrypting the local repo if the checked-out working tree is
> unprotected for all to see?  :-)
Yes. And it doesn't involve any git-specific code at all. :)
-Peff
Previous: Theodore TsoNext: David Brown
Message 12 of 17 in “[Q] Encrypted GIT?”
  1. Alexander GladyshMar 13, 2008
  2. Miklos VajnaMar 13, 2008
  3. Johannes SchindelinMar 13, 2008
  4. Miklos VajnaMar 13, 2008
  5. Theodore TsoMar 13, 2008
  6. Alexander GladyshMar 13, 2008
  7. Johannes SchindelinMar 13, 2008
  8. Jeff KingMar 13, 2008
  9. Jeff KingMar 13, 2008
  10. Jeff KingMar 13, 2008
  11. Theodore TsoMar 13, 2008
  12. Jeff KingMar 13, 2008
  13. David BrownMar 13, 2008
  14. Thomas HarningMar 13, 2008
  15. Luke LuMar 13, 2008
  16. Thomas HarningMar 13, 2008
  17. Luke LuMar 13, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.