5 ms·
Can you walk me a scenario where you and I are hosting our code on a malicious git server and Chuck can get their code in our our codebase? (assuming only signe
by kenmacd 6y ago
Can you walk me a scenario where you and I are hosting our code on a malicious git server and Chuck can get their code in our our codebase? (assuming only signed commits)
- Sebb767 6y agoSee: > if you are not careful and you do not examine git status/diff you could sign and commit the hackers change I assume he meant that you pull, get an auto merge and then inattentively sign it. With this, you confirm the hackers change with your signature. You could add a push hook to only allow fully signed chains, but given that we are talking about a compromised server, this does not help.
- Angius 6y agoBut how does the hacker's commit goes through in the first place, if all PRs with unsigned commits are rejected outright?
- Sebb767 6y agoIf he hacked the server (which was assumed in the grand parent), he can probably shut off that check rather easily
- felipelemos 6y agoAnd then you have a singled commit without a signature lying there for everyone to see and call attention to you.
- kenmacd 6y agoYou don't really pull down code though, you pull down commits. I'm not seeing a case where you sign the attackers code. You might sign a merge commit that has an attack commit somewhere in the tree, but that's very different and much more easily audited. Even if we assume the git server is completely malicious, I'm still not seeing a case where an attacker can hide a change because I didn't 'status/diff'. I'm open to considering attacks I haven't thought of though.