git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: encrypted repositories?

From
Jeff King <peff@peff.net>
Date
Jul 23, 2009, 10:40 UTC
Message-ID
<20090723104032.GB4247@coredump.intra.peff.net>
In-Reply-To
<op.uxesdcu41e62zd@merlin.emma.line.org>
On Tue, Jul 21, 2009 at 10:25:50AM +0200, Matthias Andree wrote:
Show 7 quoted lines
> >The problem is that you need to expose not just the DAG, but also the
> >hashes of trees and blobs. Because if I know you have master^, and I want
> >to send you master, then I need to know which objects are referenced by
> >master that are not referenced by master^.
> 
> Yes, you need to know that.  Not all of the push logic needs to be
> implemented on the server though.

Yes, though fetching is much harder, since the server is the one holding the information about how the transfer can be optimized. Still, you should be able to achieve roughly the same performance as http fetching from a dumb server.

Show 12 quoted lines
> Or look at commit frequency and push sources. There's always a leak
> of information even if I just upload a series of
> blah-2009MMDD-NNN.tar.lzma.gpg files... The data is going to be
> obsolete, say, 3 months; students then write the exam and then it's
> sort of public anyways. Even if your model does not entail not
> publishing exams (as opposed to embargoed press releases under
> development), but you can't prevent someone from writing their
> recollection of the problems from memory afterwards and sharing it
> with other students.
> [...]
> Is your concern that the object name (SHA1) is derived from the
> unencrypted version?

Yes. You are potentially leaking considerable information about the unencrypted contents which an attacker could use to guess those contents (especially if the file is mostly composed of low-entropy parts, like text formatting).

-Peff
Previous: Matthias AndreeNext: J-S-B
Message 16 of 17 in “encrypted repositories?”
  1. Matthias AndreeJul 17, 2009
  2. Michael J GruberJul 17, 2009
  3. Jakub NarebskiJul 17, 2009
  4. Matthias KestenholzJul 17, 2009
  5. Linus TorvaldsJul 17, 2009
  6. John TapsellJul 17, 2009
  7. Linus TorvaldsJul 17, 2009
  8. Linus TorvaldsJul 17, 2009
  9. Thomas KochJul 18, 2009
  10. Matthias AndreeJul 20, 2009
  11. Matthias AndreeJul 20, 2009
  12. Jakub NarebskiJul 20, 2009
  13. Matthias AndreeJul 21, 2009
  14. Jeff KingJul 20, 2009
  15. Matthias AndreeJul 21, 2009
  16. Jeff KingJul 23, 2009
  17. J-S-BAug 2, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.