git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Encrypted repositories

From
Enrico Weigelt <enrico.weigelt@vnc.biz>
Date
Sep 6, 2012, 13:56 UTC
Message-ID
<e1f18eed-1096-4121-879a-4dd78627a4ba@zcs>
In-Reply-To
<7vvcfr4sq3.fsf@alter.siamese.dyndns.org>
Hi,
Show 10 quoted lines
> Enrico Weigelt <enrico.weigelt@vnc.biz> writes:
> 
> > * blobs are encrypted with their (original) content hash as
> >   encryption keys
> 
> What does this even mean?
> 
> Is it expected that anybody who has access to the repository can
> learn names of objects (e.g. by running "ls .git/objects/??/")? If
> so, from whom are you protecting your repository?

Well, everybody can access the objects, but they're encrypted, so you need the repo key (which, of course isn't contained in the repo itself ;-p) to decrypt them.

The whole tree will still be consistent even without encryption support (so, gc etc shouldn't break), but to actually _use_ the repo (eg. checkout or adding new commits), you'll need the encryption support and the repo key (well, committing should theoretically even work with diffrent repo key, even this doesn't make much sense ;-)).

> How does this encryption interact with delta compression employed
> in pack generation?

Probably not at all ;-o For the usecases I have in mind (backups, filesharing, etc) this wouldn't hurt so much, if the objects are compressed before encryption.

cu
-- 
Mit freundlichen Grüßen / Kind regards 

Enrico Weigelt 
VNC - Virtual Network Consult GmbH 
Head Of Development 

Pariser Platz 4a, D-10117 Berlin
Tel.: +49 (30) 3464615-20
Fax: +49 (30) 3464615-59

enrico.weigelt@vnc.biz; www.vnc.de 
Previous: Junio C HamanoNext: Junio C Hamano
Message 3 of 6 in “Encrypted repositories”
  1. Enrico WeigeltSep 6, 2012
  2. Junio C HamanoSep 6, 2012
  3. Enrico WeigeltSep 6, 2012
  4. Junio C HamanoSep 6, 2012
  5. Enrico WeigeltSep 8, 2012
  6. David AguilarSep 8, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.