Re: Question about scm security holes
- From
Avery Pennarun <apenwarr@gmail.com>
- Date
- Mar 5, 2010, 03:19 UTC
- Message-ID
- <32541b131003041919u6a477b46s447a6aeb18f3b393@mail.gmail.com>
- In-Reply-To
- <43d8ce651003041900x66000be4s9a15ab0cde3a0fe7@mail.gmail.com>
On Thu, Mar 4, 2010 at 10:00 PM, John Tapsell <johnflux@gmail.com> wrote:
Show 8 quoted lines
> On 5 March 2010 02:03, Avery Pennarun <apenwarr@gmail.com> wrote: >> modified code would be a little more interesting. git makes this sort >> of thing pretty much impossible to do without it being *noticeable* at >> least. Traceable, not so much, because you can create a commit with >> whatever committer/author names you want and then push them in. > > Which is why you simply record the username of whoever pushed them in. > This is what gitorious.org does etc.
Not bad, but it's still very hard to trace properly. Imagine I pull from a peer, then push my combined branch into the central repo. It'll say I'm pushing in patches from me *and* my friend. Did I forge them or are they real?
Avery