git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git ransom campaign incident report - May 2019

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
May 15, 2019, 18:59 UTC
Message-ID
<8736lfwnks.fsf@evledraar.gmail.com>
In-Reply-To
<CACPiFCJdXsrywra8qPU3ebiiGQP3YPC6g-_Eohbfwu_bQgfyVg@mail.gmail.com>
On Wed, May 15 2019, Martin Langhoff wrote:
Show 13 quoted lines
> Spotted this on the internet...
>
> https://github.blog/2019-05-14-git-ransom-campaign-incident-report/
>
> Haven't hacked on git for a while, and I am not affiliated with any of
> the stakeholders. However, reading it, I wanted to slam my head on the
> desk.
>
> IIRC, git will sanely store a password elsewhere if it gets to prompt
> for it. Should we be trying to unpack usernames/passwords from HTTP
> urls, and DTRT with them?
>
> Are there other ways this could be made better?
I think we should do nothing.

The linked blog post really manages to bury the lead. I guess you'll get that when PR at three different companies gets a say. For those looking for a brief summary, here's mine:

    Some people using git hosting sites "git clone"'d https URLs to
    their repos with username/passwords in them. They then pointed a
    webserver at their checked-out directory, and got pwned by someone
    scraping "/.git/config" from public websites looking for
    credentials.

Trying to mitigate this in git is just going to annoy users who are doing this in the context of an otherwise secure workflow. The users who were affected by this are probably also the sort of users who are hardcoding their AWS password in some JavaScript checked into their project or whatever, there's only so much you can do.

It's probably more productive to say convince whoever maintains the default nginx/apache etc. docker image to default to some Fisher-Price mode where dotfiles aren't served up by default.

Or, for GitLab/GitHub etc. to discourage use of https API tokens in favor of SSH deploy keys. OpenSSH goes out of its way to not allow you to provide paswords in URLs, on the command-line etc. in anticipation of exactly this sort of scenario. Even then I've seen users write say docker images where they manage to hardcode an SSH private key in a public image out of convenience or lazyness (say needing "git clone" something during the image build).

Previous: Martin LanghoffNext: Jeff King
Message 2 of 23 in “Git ransom campaign incident report - May 2019”
  1. Martin LanghoffMay 15, 2019
  2. Ævar Arnfjörð BjarmasonMay 15, 2019
  3. Jeff KingMay 16, 2019
  4. Johannes SchindelinMay 17, 2019
  5. Jeff KingMay 17, 2019
  6. Martin LanghoffMay 17, 2019
  7. Jeff KingMay 19, 2019
  8. 1/3 transport_anonymize_url(): support retaining usernameJeff King, May 19, 2019
  9. Eric SunshineMay 19, 2019
  10. René ScharfeMay 20, 2019
  11. Johannes SchindelinMay 20, 2019
  12. Johannes SchindelinMay 20, 2019
  13. 2/3 clone: avoid storing URL passwords in configJeff King, May 19, 2019
  14. 3/3 clone: auto-enable git-credential-store when necessaryJeff King, May 19, 2019
  15. Eric SunshineMay 20, 2019
  16. Jeff KingMay 20, 2019
  17. Johannes SchindelinMay 20, 2019
  18. Ævar Arnfjörð BjarmasonMay 20, 2019
  19. Jeff KingMay 20, 2019
  20. Ævar Arnfjörð BjarmasonMay 20, 2019
  21. Jeff KingMay 20, 2019
  22. Ævar Arnfjörð BjarmasonMay 20, 2019
  23. Johannes SchindelinMay 20, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.