git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: encrypted repositories?

From
Jakub Narebski <jnareb@gmail.com>
Date
Jul 17, 2009, 20:22 UTC
Message-ID
<m3skgvt5zi.fsf@localhost.localdomain>
In-Reply-To
<4A60A168.2060105@drmicha.warpmail.net>
Michael J Gruber <git@drmicha.warpmail.net> writes:
Show 17 quoted lines
> Matthias Andree venit, vidit, dixit 17.07.2009 17:14:
> > 
> > I have a rather special usage scenario.
> > 
> > Assume you have a repository where you want to work on embargoed  
> > information, so that not even system administrators of the server you're  
> > pushing to can get a hold of the cleartext data.
> > 
> > "Server" would be a central reference repository that I can push to.
> > "Client" would by my working computer that has a clone of the crypted  
> > repo, and an unencrypted checkout of it. Perhaps the client would also  
> > need an unencrypted copy of the repo (for performance reasons, I'm not  
> > sure about that) that gets encrypted on the fly when pushing and decrypted  
> > when fetching.
> > 
> > Examples of use might be press releases of upcoming products, written  
> > exams for students, whatever.
Show 5 quoted lines
> If the server can not decrypt anything then it can not serve anything,
> at least not as a git server. Note that if you're really fussy about
> security then you should not allow the server to see even the DAG (which
> would be the case if you encrypt blobs only), which makes it impossible
> to do any smart serving.

There was shown here on git mailing list script which was meant to help in situation where you have repository with sensitive deta, discovered repository corruption or bug in git, and cannot be reproduced otherwise. But I think it didn't encrypt repositry, but just emulate it's structure.

As to encrypting repository: you can encrypt blobs (content of files), you can encrypt filenames (but the structure remains) or you can put files in a flat encrypted structure, and you can encrypt commit messages and comitter and author info, and encrypt / rename branch names. Still some DAG structure will be visible, and need be visible for "smart" git server (access via ssh and git protocols) to work.

-- 
Jakub Narebski
Poland
ShadeHawk on #git
Previous: Michael J GruberNext: Matthias Kestenholz
Message 3 of 17 in “encrypted repositories?”
  1. Matthias AndreeJul 17, 2009
  2. Michael J GruberJul 17, 2009
  3. Jakub NarebskiJul 17, 2009
  4. Matthias KestenholzJul 17, 2009
  5. Linus TorvaldsJul 17, 2009
  6. John TapsellJul 17, 2009
  7. Linus TorvaldsJul 17, 2009
  8. Linus TorvaldsJul 17, 2009
  9. Thomas KochJul 18, 2009
  10. Matthias AndreeJul 20, 2009
  11. Matthias AndreeJul 20, 2009
  12. Jakub NarebskiJul 20, 2009
  13. Matthias AndreeJul 21, 2009
  14. Jeff KingJul 20, 2009
  15. Matthias AndreeJul 21, 2009
  16. Jeff KingJul 23, 2009
  17. J-S-BAug 2, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.