git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Question about scm security holes

From
Avery Pennarun <apenwarr@gmail.com>
Date
Mar 5, 2010, 02:03 UTC
Message-ID
<32541b131003041803q9abf6baq4cf9ffcca990b51c@mail.gmail.com>
In-Reply-To
<hmp427$d6h$1@dough.gmane.org>
On Thu, Mar 4, 2010 at 3:09 PM, walt <w41ter@gmail.com> wrote:
Show 7 quoted lines
> I can't tell from the article if Perforce is any worse than any other scm
> for security holes, in fact it seems to imply that others haven't been tested in
> the same way.
>
> Just curious if anyone here has any thoughts about how the article may or
> may not have any relevance for git (git being the scm I use most, by far, which
> is the reason I'm interested).

The attack was uninteresting. The paper seems to go on and on about different ways that an attacker can steal source code by accessing a poorly-secured SCM server. This discussion is kind of moot for git, where every single developer workstation has a complete copy of the entire project history anyway.

An attack in which someone untraceably modified the repo to contain modified code would be a little more interesting. git makes this sort of thing pretty much impossible to do without it being *noticeable* at least. Traceable, not so much, because you can create a commit with whatever committer/author names you want and then push them in. Commits aren't GPG-signed, only tags are, so there are lots of ways to forge a commit from someone else and mess up the audit log. At least you can't edit old commits without people noticing, though.

Have fun,
Avery
Previous: waltNext: John Tapsell
Message 2 of 13 in “Question about scm security holes”
  1. waltMar 4, 2010
  2. Avery PennarunMar 5, 2010
  3. John TapsellMar 5, 2010
  4. Avery PennarunMar 5, 2010
  5. John TapsellMar 5, 2010
  6. waltMar 5, 2010
  7. Avery PennarunMar 5, 2010
  8. Andreas KreyMar 5, 2010
  9. Johannes SchindelinMar 5, 2010
  10. Jakub NarebskiMar 5, 2010
  11. Avery PennarunMar 5, 2010
  12. Johannes SchindelinMar 5, 2010
  13. Daniel BarkalowMar 5, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.