git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: encrypted repositories?

From
Jeff King <peff@peff.net>
Date
Jul 20, 2009, 15:30 UTC
Message-ID
<20090720153024.GD5347@coredump.intra.peff.net>
In-Reply-To
<op.uxc712eh1e62zd@balu.cs.uni-paderborn.de>
On Mon, Jul 20, 2009 at 02:09:28PM +0200, Matthias Andree wrote:
Show 9 quoted lines
> No, the server can't be allowed access to the keys or decrypted data.
> 
> I'm not sure about the graph, and if I should be concerned. Exposing
> the DAG might be in order.
> 
> It would be ok if the disk storage and the over-the-wire format
> cannot use delta compression then. It would suffice to just send a
> set of objects efficiently - and perhaps smaller revisions can be
> delta-compressed by the clients when pushing.

The problem is that you need to expose not just the DAG, but also the hashes of trees and blobs. Because if I know you have master^, and I want to send you master, then I need to know which objects are referenced by master that are not referenced by master^.

So now you have security implications, because I can do an offline guessing attack against your files (i.e., calculate git blob hashes for likely candidates and see if you have them). Whether that is a problem really depends on your data.

Not to mention that it makes the protocol a lot more complex, as you would be encrypting _parts_ of objects, like the filenames of a tree, and the commit message of a commit object.

I suppose in theory you could obfuscate the sha1's in a way that preserved the object relationships but revealed no information. That is, the server would have one "fake" set of sha1's, and the client would map its real sha1's to the fake ones when talking with the server. But that is again potentially getting complex.

-Peff
Previous: Matthias AndreeNext: Matthias Andree
Message 14 of 17 in “encrypted repositories?”
  1. Matthias AndreeJul 17, 2009
  2. Michael J GruberJul 17, 2009
  3. Jakub NarebskiJul 17, 2009
  4. Matthias KestenholzJul 17, 2009
  5. Linus TorvaldsJul 17, 2009
  6. John TapsellJul 17, 2009
  7. Linus TorvaldsJul 17, 2009
  8. Linus TorvaldsJul 17, 2009
  9. Thomas KochJul 18, 2009
  10. Matthias AndreeJul 20, 2009
  11. Matthias AndreeJul 20, 2009
  12. Jakub NarebskiJul 20, 2009
  13. Matthias AndreeJul 21, 2009
  14. Jeff KingJul 20, 2009
  15. Matthias AndreeJul 21, 2009
  16. Jeff KingJul 23, 2009
  17. J-S-BAug 2, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.