3 ms·
This is cute. It's like encrypting all of your files with the same one time pad so diff works. Also not secure at all.
by lm741 14y ago
This is cute. It's like encrypting all of your files with the same one time pad so diff works. Also not secure at all.
- Dylan16807 14y agoOh come on that's not fair. You had me thinking the code output a cipherstream and reused it. It's using a real encryption method, the only flaw is having identical blocks encrypt the same. Since this is designed to be applied to a handful of small text files (I think?) this is not a crippling flaw, only a notable one.
- agwa 14y agogit-encrypt uses AES in ECB mode. You're right that it's not as bad as reusing a one time pad, but it's still insecure. The pictures here speak volumes: https://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Electronic_codebook_.28ECB.29 https://en.wikipedia.org/wiki/Block_cipher_modes_of_operatio... It might not be crippling in most git-related use cases, but as a user you should not need to worry about your cryptosystem potentially leaking information. My project, git-crypt[1], is similar to git-encrypt but uses AES in CTR mode with a synthetic IV, which leaks only whether two entire files are identical. This is the bare minimum you need to leak to make git diffs work, and there's also a security definition called "deterministic CPA security" which CTR with a synthetic IV provably meets. [1] http://www.agwa.name/projects/git-crypt/ http://www.agwa.name/projects/git-crypt/