Re: Encrypted repositories
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Sep 6, 2012, 19:49 UTC
- Message-ID
- <7vmx132aph.fsf@alter.siamese.dyndns.org>
- In-Reply-To
- <e1f18eed-1096-4121-879a-4dd78627a4ba@zcs>
Enrico Weigelt <enrico.weigelt@vnc.biz> writes:
Show 14 quoted lines
>> Enrico Weigelt <enrico.weigelt@vnc.biz> writes: >> >> > * blobs are encrypted with their (original) content hash as >> > encryption keys >> >> What does this even mean? >> >> Is it expected that anybody who has access to the repository can >> learn names of objects (e.g. by running "ls .git/objects/??/")? If >> so, from whom are you protecting your repository? > > Well, everybody can access the objects, but they're encrypted, > so you need the repo key (which, of course isn't contained in > the repo itself ;-p) to decrypt them.
So, in short, blobs are not encrypted with the hash of their contents as encryption keys at all.
Show 7 quoted lines
>> How does this encryption interact with delta compression employed >> in pack generation? > > Probably not at all ;-o > > For the usecases I have in mind (backups, filesharing, etc) this > wouldn't hurt so much, if the objects are compressed before encryption.
For that kind of usage pattern, you are better off looking at encrypted tarballs or zip archives.