git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Privacy

From
Nnick <nick@nicholasjohnson.ch>
Date
Jul 17, 2023, 04:20 UTC
Message-ID
<CU45QDSITT7K.1HLDIM21MXW7H@anonymous>
In-Reply-To
<00b901d9b83d$249a2d20$6dce8760$@pdinc.us>
Jason Pyeron wrote:
Show 9 quoted lines
> > nick wrote:
> > Come to think of it, even if timezones were converted to UTC by default,
> > time of day would still leak information about a user's likely timezone.
>
> Discussed this with our policy wonks...
>
> Short answer - no. There is no legal assumption that can be made - your
> work hours cannot be assumed to be 9-5. They also said that time zone is
> "too broad at 1/24th of the world", but understood the concern.

An adversary may have other information which can be correlated with the timestamps or timezone, making them less benign than in isolation.

> That being said the recommendation is to add --privacy

I'm not familiar with the processes here. Is it my responsibility to implement it since I proposed it or who shall implement it?

Show 8 quoted lines
> Where it assumes some defaults and those defaults can be controlled in
> your config or via --privacy=option1,option2
>
> And then some of the options can be:
>
> date-timezone=UTC
>
> date-precision=8hour
This sounds great. A few preliminary ideas on implementation:

'date-precision' must round the author AND committer timestamps otherwise it's useless

'date-precision' must round down, never into the future

'date-timezone' must convert the date from local time and not just replace the timezone

Any thoughts on making 'date-precision' also apply to GnuPG signature timestamps? It's possible to specify a custom GnuPG command which does this using gpg.program, but it's inconvenient. The relevant GnuPG option is '--faked-system-time <epoch>!'

If that idea is no good, there should at least be a warning displayed when the user signs anything with GnuPG with 'date-precision' enabled.

If that idea is good, then there should be a conditional check that the rounding performed by 'date-precision' does not round down to before the signing key was generated. Otherwise the signature will be invalid.

Previous: Jason PyeronNext: brian m. carlson
Message 16 of 17 in “Git Privacy”
  1. nickJul 13, 2023
  2. Junio C HamanoJul 13, 2023
  3. nickJul 14, 2023
  4. Junio C HamanoJul 14, 2023
  5. nickJul 15, 2023
  6. René ScharfeJul 16, 2023
  7. nickJul 16, 2023
  8. Junio C HamanoJul 17, 2023
  9. Junio C HamanoJul 17, 2023
  10. nickJul 17, 2023
  11. Theodore Ts'oJul 17, 2023
  12. nickJul 17, 2023
  13. Junio C HamanoJul 17, 2023
  14. nickJul 16, 2023
  15. Jason PyeronJul 16, 2023
  16. nickJul 17, 2023
  17. brian m. carlsonJul 18, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.