git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git Privacy

From
Junio C Hamano <gitster@pobox.com>
Date
Jul 17, 2023, 02:57 UTC
Message-ID
<xmqq5y6jjlcs.fsf@gitster.g>
In-Reply-To
<xmqqsf9njmc9.fsf@gitster.g>
Junio C Hamano <gitster@pobox.com> writes:
Show 7 quoted lines
> and just use them), we should NOT be adding a "--privacy" option
> that picks rand(24)*60 as UTC offset and pretends that it the
> timezone of the author, and picks some random timestamp between the
> timestamp of the latest commit in the repository and the actual
> wallclock timestamp and pretends that is the author time.  After
> all, our project is not about coming up with a quality time
> obfusucation.

We could go to the extreme in the complete opposite, if we do not care about the quality of the "privacy" feature, and you could probably talk me into adopting below as long as the option or the configuration are not named with the word "privacy" in them (a "--useless-time" option, or a "core.uselesstime" configuration variable, are OK).

When the feature is in effect, all timestamps in commit and tag objects pretend to be in UTC timezone, and

 (1) the commits record the Epoch as its timestamps if there is no
     parent;
 (2) the commits record one second after the largest of the
     timestamps as its timestamps of all its parents;
 (3) in any case, the same (phoney) timestamp is used for author and
     committer.
 (4) the tags record the Epoch as its timestamp if they point at
     trees or blobs.
 (5) the tags record one second after the largest timestamp of
     pointee as their timestamp, if they point at tags or commits.
 (6) as the reflog is a local matter, its timestamp may be local,
     but it is OK if it ends up being just a useless number if that
     is more convenient to implement.

The resulting history will be shouting that "I am privacy conscious and hiding my activities behind a fake clock" in capital letters, which I would not call a quality design of a privacy feature, but it does completely dissociate the wallclock time from the recorded history without breaking the monotonicity of timestamps in the recorded history.

When the useless-time feature is in use, you cannot expect features like "git log --since" would work sensibly, but that is a given, I would guess.

Previous: Junio C HamanoNext: nick
Message 9 of 17 in “Git Privacy”
  1. nickJul 13, 2023
  2. Junio C HamanoJul 13, 2023
  3. nickJul 14, 2023
  4. Junio C HamanoJul 14, 2023
  5. nickJul 15, 2023
  6. René ScharfeJul 16, 2023
  7. nickJul 16, 2023
  8. Junio C HamanoJul 17, 2023
  9. Junio C HamanoJul 17, 2023
  10. nickJul 17, 2023
  11. Theodore Ts'oJul 17, 2023
  12. nickJul 17, 2023
  13. Junio C HamanoJul 17, 2023
  14. nickJul 16, 2023
  15. Jason PyeronJul 16, 2023
  16. nickJul 17, 2023
  17. brian m. carlsonJul 18, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.