3 ms·
Is signing every commit really that useful?
by samwestdev 7y ago
Is signing every commit really that useful?
- trishankdatadog 7y agoIf you care about who produced your source code, yes.
- rgoulter 7y agoI think "sign every commit useful?" is less about whether signing is useful, and more about the trade-off of signing every commit vs just signing a tag on a commit. Signing every commit is going to make it a mindless task. It's easier to be vigilant when signing if you sign less frequently. What trade-offs should be considered?
- philsnow 7y agogit config --global commit.gpgsign true this turns commit signing on for every commit, you don't have to explicitly sign commits as a separate step. the criticism I've always heard of this practice is, what do you do with those signatures? github displays a little widget showing that the commits are signed, but beyond that I don't think it cares which public key they were signed with, so it's not really helping anything.
- rgoulter 7y ago> this turns commit signing on for every commit My understanding is: Entering a key passphrase each time is going to be annoying without providing benefit over just signing some git tag. Leaving the key unlocked in an agent is going to be somewhat less secure than requiring the key to be unlocked on every use. > github displays a little widget showing that the commits are signed, but beyond that I don't think it cares which public key they were signed with, so it's not really helping anything. As I understand it, "verified" means it's either a commit made on GitHub's website with that user signed in, or the commit was signed with one of the keys associated with that user's profile. I guess for the case of "I only trust commits signed by a certain key", you'd need to use a different GitHub profile.
- sixstringtheory 7y agoIt is simply an audit trail to trace back to the origin, since anyone can set any email address as the author of a commit. GitHub will show the signature fingerprint I think when you hover over that widget, so you can at least distinguish between your key and an impostor’s. I use this but it causes weird usability issues for me when using multiple iTerm tabs or git GUIs when the GPG daemon’s unlock timeout expires and I need to input my passphrase in again. I wish it could just be tied to the mac’s keychain, so when I unlock my computer it is ready to go. Or at least tie it into TouchID or Watch like unlocking the mac does.
- trishankdatadog 7y agoYes, it's so easy with this YK setup that there's no reason not to do it. The only exception is during rebase, but there's an option in GPG to disable signing then. I sign all my commits so that everyone knows it was most likely me. You can even turn on branch protection in GitHub these days that rejects unsigned commits. With all due respect, Mr. Torvalds isn't exactly famous for having designed the most secure kernel.
- trishankdatadog 7y agoGentoo org was hacked on GitHub, and had their source code modified. Luckily, their private build infrastructure used only their own personal git repo, which required signing all commits (and presumably checking them). https://www.gentoo.org/news/2018/06/28/Github-gentoo-org-hacked.html https://www.gentoo.org/news/2018/06/28/Github-gentoo-org-hac... You can even turn on branch protection in GitHub these days that rejects unsigned commits. https://help.github.com/en/github/administering-a-repository/enabling-required-commit-signing https://help.github.com/en/github/administering-a-repository...
- jlgaddis 7y agoLinus says "don't do it" [0]: > Signing each commit is totally stupid. It just means that you automate it, and you make the signature worth less. It also doesn't add any real value, since the way the git DAG-chain of SHA1's work, you only ever need _one_ signature to make all the commits reachable from that one be effectively covered by that one. So signing each commit is simply missing the point. [0]: http://git.661346.n2.nabble.com/GPG-signing-for-git-commit-tp2582986p2583316.html http://git.661346.n2.nabble.com/GPG-signing-for-git-commit-t...