git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Q] Encrypted GIT?

From
LLLuke Lu <git@vicaya.com>
Date
Mar 13, 2008, 20:06 UTC
Message-ID
<8F9BA906-777F-4B7D-BA19-D0848D1886B3@vicaya.com>
In-Reply-To
<20080313151532.20d72b14@gmail.com>
On Mar 13, 2008, at 12:15 PM, Thomas Harning wrote:
Show 18 quoted lines
> On Thu, 13 Mar 2008 11:36:46 -0700
> Luke Lu <git@vicaya.com> wrote:
>
>> An obvious and easy solution: use an encrypted partition on the
>> remote server and ssh as transport. Last time I checked, git on
>> encrypted volumes is plenty fast.
>
> If its an encrypted partition on the remote server... then its visible
> @ that server.. which I don't think is desired in the situation.
>
> An encrypted partition is fairly useless on a remote server unless the
> remote server is expected to be physically removed/powered down...
> otherwise anything can get into that data while its alive (pending
> permissions, lack-of-holes, etc..)
>
> The encfs solution makes sure that nothing is ever revealed
> remote-side... all data is prevented from even going over ssh in its
> unencrypted form.

Yes encfs over an sshfs is probably the safest. But it is intolerably slow if you need any kind of random access of data, which git does all the time. You can mount the encrypted partition using a key over ssh per git push or pull to minimize exposure while get the performance you want.

__Luke
Previous: Thomas Harning
Message 17 of 17 in “[Q] Encrypted GIT?”
  1. Alexander GladyshMar 13, 2008
  2. Miklos VajnaMar 13, 2008
  3. Johannes SchindelinMar 13, 2008
  4. Miklos VajnaMar 13, 2008
  5. Theodore TsoMar 13, 2008
  6. Alexander GladyshMar 13, 2008
  7. Johannes SchindelinMar 13, 2008
  8. Jeff KingMar 13, 2008
  9. Jeff KingMar 13, 2008
  10. Jeff KingMar 13, 2008
  11. Theodore TsoMar 13, 2008
  12. Jeff KingMar 13, 2008
  13. David BrownMar 13, 2008
  14. Thomas HarningMar 13, 2008
  15. Luke LuMar 13, 2008
  16. Thomas HarningMar 13, 2008
  17. Luke LuMar 13, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.