git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Privacy

From
Nnick <nick@nicholasjohnson.ch>
Date
Jul 14, 2023, 09:22 UTC
Message-ID
<CU1SAE4WGP3X.3R7TTIWFSHGDI@anonymous>
In-Reply-To
<xmqqlefjpwif.fsf@gitster.g>
Show 8 quoted lines
> "nick" <nick@nicholasjohnson.ch> writes:
>
> > hooks. Perhaps a config option to automatically set the date to a time
> > before Git was invented?
>
> [...] I am not yet convinced that it is worth the engineering effort
> for this project to review, accept and maintain changes to implement
> it.

Upon further thought, given that it's already pretty easy to accomplish timestamp obfuscation, albeit clumsy, I concede that it may not be worth the engineering effort to implement my original suggestion. So I'll drop it.

However, I think it is worth the effort for the time zones. Is there any reason Git doesn't automatically convert local time to UTC in timestamps to prevent leaking the developer's time zone?

It seems like a simple change that would be good for the developer's privacy without harming Git in any way. It would also be easy to implement as backwards-compatible.

I've been told this idea was already mentioned, but it has been ignored for some time:

https://git.issues.gerritcodereview.com/issues/40000039

The sooner it's addressed, the better since it means less personal information leakage.

Show 9 quoted lines
> After all, if you leave series of commits that stress the fact that
> you not just fail to keep, but do deliberately avoid to keep, a
> reliable record of when you made your changes, half the value of
> keeping your work in source code management system vanishes. When
> somebody comes to your project and says certain parts of your code
> were stolen from their proprietary IP, wouldn't you rather be able
> to produce the record of who did what at which time to refute their
> claim by showing that your project members invented the code long
> before they claim they were stolen from them?

Thank you for bringing this up. This was not an angle I considered when writing my repo git-privacy, but now I'll definitely warn about it there.

Your feedback above would not apply to the UTC time zone proposal I linked to though. There is a good reason to implement it and, as far as I can think of, no reason not to.

Previous: Junio C HamanoNext: Junio C Hamano
Message 3 of 17 in “Git Privacy”
  1. nickJul 13, 2023
  2. Junio C HamanoJul 13, 2023
  3. nickJul 14, 2023
  4. Junio C HamanoJul 14, 2023
  5. nickJul 15, 2023
  6. René ScharfeJul 16, 2023
  7. nickJul 16, 2023
  8. Junio C HamanoJul 17, 2023
  9. Junio C HamanoJul 17, 2023
  10. nickJul 17, 2023
  11. Theodore Ts'oJul 17, 2023
  12. nickJul 17, 2023
  13. Junio C HamanoJul 17, 2023
  14. nickJul 16, 2023
  15. Jason PyeronJul 16, 2023
  16. nickJul 17, 2023
  17. brian m. carlsonJul 18, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.