git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Encrypted repositories

From
David Aguilar <davvid@gmail.com>
Date
Sep 8, 2012, 04:10 UTC
Message-ID
<CAJDDKr7kheuOoeiCyvh8eZTGTR3u8JZxaveKX8TyBrmLMA4msw@mail.gmail.com>
In-Reply-To
<0666bd29-b156-4c3d-b859-ab140d2f849e@zcs>
On Fri, Sep 7, 2012 at 8:34 PM, Enrico Weigelt <enrico.weigelt@vnc.biz> wrote:
Show 23 quoted lines
>
>> > Well, everybody can access the objects, but they're encrypted,
>> > so you need the repo key (which, of course isn't contained in
>> > the repo itself ;-p) to decrypt them.
>>
>> So, in short, blobs are not encrypted with the hash of their
>> contents as encryption keys at all.
>
> No, the blobs are encrypted with their content hash as key, and the
> encrypted blob will be stored with it's content hash as object id.
>
>> > For the usecases I have in mind (backups, filesharing, etc) this
>> > wouldn't hurt so much, if the objects are compressed before
>> > encryption.
>>
>> For that kind of usage pattern, you are better off looking at
>> encrypted tarballs or zip archives.
>
> No, that doesn't give us anything like history, incremental
> synchronization, etc, etc.
>
> What I finnaly wanna has is a usual git, just with encryption,
> but I can live with loosing differential compression.
Something like this?
https://gist.github.com/873637

I've never tried it myself, who knows if it works, but google found it when I searched for "git clean smudge filter encryption".

I hope that helps,
-- 
David
Previous: Enrico Weigelt
Message 6 of 6 in “Encrypted repositories”
  1. Enrico WeigeltSep 6, 2012
  2. Junio C HamanoSep 6, 2012
  3. Enrico WeigeltSep 6, 2012
  4. Junio C HamanoSep 6, 2012
  5. Enrico WeigeltSep 8, 2012
  6. David AguilarSep 8, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.