4 ms·
I wonder if the signed features of GitHub would have helped here. Probably can't ask all the 3rd party contributors to setup signing commits, but it would help
by iBotPeaches 6y ago
I wonder if the signed features of GitHub would have helped here. Probably can't ask all the 3rd party contributors to setup signing commits, but it would help to spot commits not signed.
- trulyrandom 6y agoIf the attackers would have used their own name/email linked to a GitHub account and signed the backdoor commits, GitHub would display a green "Signed" label, and everything would look OK to an outsider.
- megous 6y agoThat's why it's just a gimmick. Signing only works as protection against hosting compromise if the signing/verification is separate from the hosting itself. Someone responsible for release would have to manually keep a list of keys of authorized comiters and check the repository against this list at the very least prior to a release.
- kenmacd 6y agoIt's not about the green label. A set if commits signed by some unknown person is a lot easier to spot and clean up. Looking at these commits they say mid-2017. Without signatures any previous commit could be by the same author.
- taspeotis 6y ago> I wonder if the signed features of GitHub Uh, you mean the features of ... Git?