git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Fetch/push lets a malicious server steal the targets of "have" lines

From
Junio C Hamano <gitster@pobox.com>
Date
Oct 30, 2016, 08:03 UTC
Message-ID
<xmqqtwbuuuuy.fsf@gitster.mtv.corp.google.com>
In-Reply-To
<1477757268.1524.20.camel@mattmccutchen.net>
Matt McCutchen <matt@mattmccutchen.net> writes:
Show 16 quoted lines
> On Fri, 2016-10-28 at 22:31 -0700, Junio C Hamano wrote:
>> Not sending to the list, where mails from Gmail/phone is known to get
>> rejected.
>
> [I guess I can go ahead and quote this to the list.]
>
>> No. I'm saying that the scenario you gave is bad and people should be
>> taught not to connect to untrustworthy sites.
>
> To clarify, are you saying:
>
> (1) don't connect to an untrusted server ever (e.g., we don't promise
> that the server can't execute arbitrary code on the client), or
>
> (2) don't connect to an untrusted server if the client repository has
> data that needs to be kept secret from the server?

You sneaked "arbitrary code execution" into the discussion but I do not know where it came from. In any case, "don't pull from or push to untrustworthy place" would be a common sense advice that would make sense in any scenario ;-)

Just for future reference, when you have ideas/issues that might have possible security ramifications, I'd prefer to see it first discussed on a private list we created for that exact purpose, until we can assess the impact (if any). Right now MaintNotes says this:

    If you think you found a security-sensitive issue and want to disclose
    it to us without announcing it to wider public, please contact us at
    our security mailing list <git-security@googlegroups.com>.  This is
    a closed list that is limited to people who need to know early about
    vulnerabilities, including:
      - people triaging and fixing reported vulnerabilities
      - people operating major git hosting sites with many users
      - people packaging and distributing git to large numbers of people
    where these issues are discussed without risk of the information
    leaking out before we're ready to make public announcements.

We may want to tweak the description from "disclose it to us" to "have a discussion on it with us" (the former makes it sound as if the topic has to be a definite problem, the latter can include an idle speculation that may not be realistic attack vector).

Previous: Matt McCutchenNext: Matt McCutchen
Message 23 of 24 in “Fetch/push lets a malicious server steal the targets of "have" lines”
  1. Matt McCutchenOct 28, 2016
  2. Junio C HamanoOct 28, 2016
  3. Matt McCutchenOct 28, 2016
  4. Junio C HamanoOct 29, 2016
  5. Matt McCutchenOct 29, 2016
  6. Jeff KingOct 29, 2016
  7. Matt McCutchenOct 29, 2016
  8. Jeff KingOct 29, 2016
  9. Junio C HamanoOct 30, 2016
  10. fetch/push: document that private data can be leakedMatt McCutchen, Nov 13, 2016
  11. Junio C HamanoNov 14, 2016
  12. Matt McCutchenNov 14, 2016
  13. doc: mention transfer data leaks in more placesMatt McCutchen, Nov 14, 2016
  14. Junio C HamanoNov 14, 2016
  15. Junio C HamanoNov 14, 2016
  16. Jeff KingNov 14, 2016
  17. Junio C HamanoNov 14, 2016
  18. Matt McCutchenNov 14, 2016
  19. Jon LoeligerOct 29, 2016
  20. Junio C HamanoOct 30, 2016
  21. Matt McCutchenNov 13, 2016
  22. Matt McCutchenOct 29, 2016
  23. Junio C HamanoOct 30, 2016
  24. Matt McCutchenNov 13, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.