git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: is gitosis secure?

From
martin <martin@siamect.com>
Date
Dec 14, 2008, 09:42 UTC
Message-ID
<4944D4F7.7050501@siamect.com>
In-Reply-To
<alpine.DEB.1.10.0812132126470.17688@asgard.lang.hm>

Dear David. Why do you trust VPN more than the SSH? I ask because I have just removed the "first VPN then SSH" solution in favor for a SSH only solution using Gitosis just to get rid of the VPN which I believe is less secure than SSH (well until I read you comments below). I thought I was doing something right for once but maybe I'm not? Thanks and best regards Martin

david@lang.hm wrote:
Show 61 quoted lines
> this is really a reply to an earlier message that I deleted.
>
> the question was asked 'what would the security people like instead of 
> SSH'
>
> as a security person who doesn't like how ssh is used for everything, 
> let me list a couple of concerns.
>
> ssh is default allow (it lets you run any commands), you can lock it 
> down with effort.
>
> ssh defaults to establishing a tunnel between machines that other 
> network traffic can use to bypass your system. yes I know that with 
> enough effort and control of both systems you can tunnel over 
> anything, the point is that ssh is eager to do this for you (overly 
> eager IMHO)
>
> ssh depends primarily on certificates that reside on untrusted 
> machines. it can be made to work with tokens or such, but it takes a 
> fair bit of effort.
>
> sshd runs as root on just about every system
>
> people trust ssh too much. they tend to think that anything is 
> acceptable if it's done over ssh (this isn't a technical issue, but it 
> is a social issue)
>
>
> what would I like to see in an ideal world?
>
> something that runs as the git user, does not enable tunneling, and 
> only does the data transfer functions needed for a push. it should use 
> off-the-shelf libraries for certificate authentication and tie into 
> PAM for additional authentication.
>
> the authentication would not be any better than with SSH, but the rest 
> would be better. I was very pleased to watch the git-daemon 
> development, and the emphisis on it running with minimum privilages 
> and provide just the functionality that was needed, and appropriately 
> assuming that any connection from the outside is hostile until proven 
> otherwise.
>
>
> what would I do with current tools?
>
> I would say that developers working from outside should VPN into the 
> company network before doing the push with SSH rather than exposing 
> the SSH daemon to the entire Internet.
>
> in the medium term, if the git-over-http gets finished, I would like 
> to see a seperate cgi created to allow push as well. http is overused 
> as a tunneling protocol, but it's easy to setup a server that can't do 
> anything except what you want, so this tunneling is generally not a 
> threat to servers (it's a horrible threat to client systems)
>
> David Lang
> -- 
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>
Previous: david@lang.hmNext: david@lang.hm
Message 19 of 41 in “is gitosis secure?”
  1. Thomas KochDec 9, 2008
  2. Sam VilainDec 9, 2008
  3. Florian WeimerJan 18, 2009
  4. Boyd Stephen Smith Jr.Jan 18, 2009
  5. Florian WeimerJan 18, 2009
  6. Boyd Stephen Smith Jr.Jan 18, 2009
  7. Tommi VirtanenFeb 3, 2009
  8. Stephen R. van den BergFeb 4, 2009
  9. Tommi VirtanenFeb 4, 2009
  10. Stephen R. van den BergFeb 5, 2009
  11. Tommi VirtanenFeb 5, 2009
  12. R. Tyler BallanceDec 9, 2008
  13. Tommi VirtanenFeb 3, 2009
  14. Sverre RabbelierDec 9, 2008
  15. NixDec 13, 2008
  16. Sverre RabbelierDec 13, 2008
  17. Sitaram ChamartyDec 14, 2008
  18. david@lang.hmDec 14, 2008
  19. martinDec 14, 2008
  20. david@lang.hmDec 14, 2008
  21. Jakub NarebskiDec 14, 2008
  22. david@lang.hmDec 15, 2008
  23. martinDec 14, 2008
  24. david@lang.hmDec 15, 2008
  25. Mike HommeyDec 15, 2008
  26. david@lang.hmDec 15, 2008
  27. Mike HommeyDec 15, 2008
  28. TaitDec 15, 2008
  29. Sitaram ChamartyDec 14, 2008
  30. david@lang.hmDec 15, 2008
  31. Jakub NarebskiDec 14, 2008
  32. david@lang.hmDec 15, 2008
  33. Rogan DawesDec 15, 2008
  34. david@lang.hmDec 15, 2008
  35. Rogan DawesDec 15, 2008
  36. Jakub NarebskiDec 14, 2008
  37. NixDec 15, 2008
  38. david@lang.hmDec 15, 2008
  39. Asheesh LaroiaDec 15, 2008
  40. david@lang.hmDec 15, 2008
  41. Garry DolleyDec 9, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.