git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Privacy

From
Theodore Ts'o <tytso@mit.edu>
Date
Jul 17, 2023, 20:57 UTC
Message-ID
<20230717205750.GA3901704@mit.edu>
In-Reply-To
<CU47D1G1Y1E2.GID9E4XI7W1K@anonymous>
On Mon, Jul 17, 2023 at 05:36:48AM +0000, nick wrote:
> 
> I hadn't considered it in my other responses, but calling it --privacy
> would be a bad idea for exactly the reasons you laid out. Calling it
> --useless-time would be better.

It might also be worth pointing out that someone still might be able to figure out information from when a branch gets pushed to a git repo. Even if the time in the timestamp is randomized, when someone sends a pull request to github is not going to be randomize. Or if someone pushes their branch to github, and github actions is set up to automatically kick off regression tests as soon as the branch changes, this can also leak information about when the push happened.

There are also integration test systems, such as the gce-xfstests's lightweight test manager, which polls the branch every 15 minutes, and the moment the branch changes, tests immediately start running and the timestamp when the test was kicked off is encoded in the testrunid.

Which is why, quite frankly, I'm a bit dubious about the whole "I must obfuscate the time zone from which I am operating", as something that's really worth the effort, since it has a lot of downsides, and if the user is not careful, they may end up leaking information about when they are active anyway....

					- Ted
Previous: nickNext: nick
Message 11 of 17 in “Git Privacy”
  1. nickJul 13, 2023
  2. Junio C HamanoJul 13, 2023
  3. nickJul 14, 2023
  4. Junio C HamanoJul 14, 2023
  5. nickJul 15, 2023
  6. René ScharfeJul 16, 2023
  7. nickJul 16, 2023
  8. Junio C HamanoJul 17, 2023
  9. Junio C HamanoJul 17, 2023
  10. nickJul 17, 2023
  11. Theodore Ts'oJul 17, 2023
  12. nickJul 17, 2023
  13. Junio C HamanoJul 17, 2023
  14. nickJul 16, 2023
  15. Jason PyeronJul 16, 2023
  16. nickJul 17, 2023
  17. brian m. carlsonJul 18, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.