git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git:// protocol over SSL/TLS

From
Matthieu Moy <matthieu.moy@grenoble-inp.fr>
Date
Dec 27, 2013, 14:20 UTC
Message-ID
<vpqwqiqpe80.fsf@anie.imag.fr>
In-Reply-To
<87mwjm4c3s.fsf@igel.home>
Andreas Schwab <schwab@linux-m68k.org> writes:
Show 8 quoted lines
> Sergey Sharybin <sergey.vfx@gmail.com> writes:
>
>> So guess we just need to recommend using https:// protocol instead of
>> git:// for our users?
>
> Given how easy it is to verify the integrity of a git repository out of
> band there isn't really much of added security by using TLS for
> transport.

You can verify integrity after the fact, but not guarantee confidentiality ... so it again depends on the definition of "security".

-- 
Matthieu Moy
http://www-verimag.imag.fr/~moy/
Previous: Sergey SharybinNext: Sergey Sharybin
Message 8 of 21 in “git:// protocol over SSL/TLS”
  1. Sergey SharybinDec 27, 2013
  2. Andreas SchwabDec 27, 2013
  3. Konstantin KhomoutovDec 27, 2013
  4. Sergey SharybinDec 27, 2013
  5. Andreas SchwabDec 27, 2013
  6. Konstantin KhomoutovDec 27, 2013
  7. Sergey SharybinDec 27, 2013
  8. Matthieu MoyDec 27, 2013
  9. Sergey SharybinDec 27, 2013
  10. Konstantin KhomoutovDec 27, 2013
  11. Sergey SharybinDec 27, 2013
  12. Konstantin KhomoutovDec 27, 2013
  13. Jeff KingDec 28, 2013
  14. Bernhard R. LinkDec 27, 2013
  15. Sergey SharybinDec 28, 2013
  16. brian m. carlsonDec 28, 2013
  17. Andreas SchwabDec 27, 2013
  18. Pyeron, Jason J CTR (US)Dec 27, 2013
  19. Konstantin KhomoutovDec 27, 2013
  20. Junio C HamanoDec 27, 2013
  21. Ilari LiusvaaraDec 28, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.