Re: [git patches] libata updates, GPG signed (but see admin notes)
- From
- Ingo Molnar <mingo@elte.hu>
- Date
- Nov 2, 2011, 09:11 UTC
- Message-ID
- <20111102091126.GG18903@elte.hu>
- In-Reply-To
- <CA+55aFyKWLUMQFfaeKJKGFPV_7kfOGjf+pSZ1Y8afzkT4OYQ9Q@mail.gmail.com>
* Linus Torvalds <torvalds@linux-foundation.org> wrote:
> And the receiving side would just do the "git pull" and > automatically just get notified that "Yes, this push has been > signed by key Xyz Abcdef"
If this approach is used then it would be nice to have a .gitconfig switch to require trusted pulls by default: to not allow doing non-signed or untrusted pulls accidentally, or for Git to warn in a visible, hard to miss way if there's a non-signed pull.
This adds social uncertainty (and an element of a silent alarm) to a realistic attack: the attacker wouldnt know exactly how the puller checks signed pull requests, it's kept private.
Thanks,
Ingo