From mboxrd@z Thu Jan 1 00:00:00 1970 From: Jeff King Subject: Re: [Q] Encrypted GIT? Date: Thu, 13 Mar 2008 12:01:54 -0400 Message-ID: <20080313160154.GC30847@coredump.intra.peff.net> References: <20080313114738.GC2414@genesis.frugalware.org> <20080313121644.GD2414@genesis.frugalware.org> <20080313125853.GA12927@mit.edu> <20080313155322.GA30847@coredump.intra.peff.net> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Cc: Miklos Vajna , Johannes Schindelin , Alexander Gladysh , git@vger.kernel.org To: Theodore Tso X-From: git-owner@vger.kernel.org Thu Mar 13 17:03:18 2008 Return-path: Envelope-to: gcvg-git-2@gmane.org Received: from vger.kernel.org ([209.132.176.167]) by lo.gmane.org with esmtp (Exim 4.50) id 1JZptg-0001FG-Ex for gcvg-git-2@gmane.org; Thu, 13 Mar 2008 17:03:12 +0100 Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753725AbYCMQB6 (ORCPT ); Thu, 13 Mar 2008 12:01:58 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1752203AbYCMQB5 (ORCPT ); Thu, 13 Mar 2008 12:01:57 -0400 Received: from 66-23-211-5.clients.speedfactory.net ([66.23.211.5]:4335 "EHLO peff.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752000AbYCMQB5 (ORCPT ); Thu, 13 Mar 2008 12:01:57 -0400 Received: (qmail 10085 invoked by uid 111); 13 Mar 2008 16:01:55 -0000 Received: from coredump.intra.peff.net (HELO coredump.intra.peff.net) (10.0.0.2) by peff.net (qpsmtpd/0.32) with SMTP; Thu, 13 Mar 2008 12:01:55 -0400 Received: by coredump.intra.peff.net (sSMTP sendmail emulation); Thu, 13 Mar 2008 12:01:54 -0400 Content-Disposition: inline In-Reply-To: <20080313155322.GA30847@coredump.intra.peff.net> Sender: git-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: git@vger.kernel.org Archived-At: On Thu, Mar 13, 2008 at 11:53:22AM -0400, Jeff King wrote: > You could probably do something totally external to git using bundles as > the primitive. Store an encrypted index on the remote that says "here > are the packs I have, and the objects they contain." Whenever you push, > pull the index (which is of course more network-intensive than regular > git protocol, but not as bad as pulling all the data) and calculate a > thin-pack bundle yourself. Encrypt the bundle and store remotely. Oh, and a scheme like this generalizes well from "there is one key" to "N asymmetric keyholders". > I don't know if a formal thread analysis is necessary. I think most That should of course be "threa_t_ analysis". I of course want to formally analyze this thread. ;) -Peff