git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Privacy

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Jul 18, 2023, 21:59 UTC
Message-ID
<ZLcLQZfZK+QnG5cx@tapette.crustytoothpaste.net>
In-Reply-To
<CU3Z2NYP6BGG.1PQ6S5AF60XX6@anonymous>
On 2023-07-16 at 23:07:06, nick wrote:
Show 8 quoted lines
> nick wrote:
> > The time zones reveal private information about developers and they
> > don't even serve a use case, as far as I'm aware. A backwards-compatible
> > way to solve this leak would be to convert timestamps to UTC by default
> > and have a Git config option to revert back to the current behavior.
> 
> Come to think of it, even if timezones were converted to UTC by default,
> time of day would still leak information about a user's likely timezone.

This is true. My .signature indicates where I'm located (which isn't a secret), but I have `TZ=UTC` set in my shell config. You'll notice that my timestamp is +0000 in all my commits. I keep a reasonably regular daytime schedule, so it's easy to tell what my hours are.

Show 5 quoted lines
> So based on that and keeping in mind Git's desire for strong
> backwards-compatibility, I'm amending my proposal to just a standalone
> Git option which would allow for forging timestamp and timezone
> information, with timestamp information being forgeable to varying
> degrees of granularity.

One thing I've wanted Git to do (which I'm not sure is backwards compatible) is to set the timezone to -0000 (instead of +0000) to indicate that the user has intentionally refused to set the timezone, much like the equivalent syntax in RFC 5322. I think that's a fine choice for lots of reasons, but it prevents people from accidentally concluding that I live in Reykjavík and expecting a response from me when I'm actually in bed.

I'd support a command-line and config option that did that, in addition to an option that adjusted the timezone.

-- 
brian m. carlson (he/him or they/them)
Toronto, Ontario, CA
Previous: nick
Message 17 of 17 in “Git Privacy”
  1. nickJul 13, 2023
  2. Junio C HamanoJul 13, 2023
  3. nickJul 14, 2023
  4. Junio C HamanoJul 14, 2023
  5. nickJul 15, 2023
  6. René ScharfeJul 16, 2023
  7. nickJul 16, 2023
  8. Junio C HamanoJul 17, 2023
  9. Junio C HamanoJul 17, 2023
  10. nickJul 17, 2023
  11. Theodore Ts'oJul 17, 2023
  12. nickJul 17, 2023
  13. Junio C HamanoJul 17, 2023
  14. nickJul 16, 2023
  15. Jason PyeronJul 16, 2023
  16. nickJul 17, 2023
  17. brian m. carlsonJul 18, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.