Git as an Encrypted Distributed Version Control System
oai.dtic.mil
oai.dtic.mil
Alternatives:
* https://github.com/AGWA/git-crypt
* https://github.com/shadowhand/git-encrypt
* http://docs.ansible.com/ansible/playbooks_vault.html
* https://github.com/elasticdog/transcrypt
* http://www.passwordstore.org/
[0]: https://github.com/StackExchange/blackboxThe paper mentions that it's measuring the worst-case scenario for the clean/smudge filter-style tools as it's much more likely that you only need to protect a few files and not the entire repository, but I didn't see how the second section actually reflected this more-realistic scenario. I'm not saying that encrypting the entire repository is bad, but the overhead of using filters to encrypt the entire repository is a documented/known limitation of the other tools...so it seems a little odd to gloss over that.
Side note, stuff like "This process is repeated a total of 10 iterations for an ample sample size to draw statistical conclusions." worries me, but that's another conversation.
Overall though, glad to see more research in this area, and it sounds like GV2 might be a decent solution for people looking to protect their data in certain scenarios.
My needs are such that I might only want to encrypt a few files, and filters do an adequate job here. But I can understand a limitation where all objects must be encrypted, and thus filter perf is not appropriate.
Filters also have the limitation of leaking the commit and tree information, which may also be sensitive data on some projects.
This is an interesting strategy, and I'm glad to see more research done here, regardless.
https://github.com/rustyio/git-gpg
As the name suggests, it uses gpg to encrypt and decrypt the data.
Unlike git-encrypt and git-crypt, it doesn't use smudge/clean filters.
Instead, it uses a special command (`git-gpg push $remote`) to push changes to a local unencrypted mirror of the remote repository. It then encrypts any newly created git objects, and finally rsyncs the new objects to the remote repository. So the remote is just a directory of zipped, gpg-encrypted files.
It has worked well for me over the past two years, but I don't expect that it solves every edge case.
Feedback welcomed through issues and pull requests.
See [0] for more. Obviously, this might be overkill for your use case, but this is the "right" way to do it.
[0] https://www.kernel.org/pub/software/scm/git/docs/gitremote-h...
Significance of Research
As stated in Chapter I, distributed version control systems, particularly Git, have been rapidly increasing in popularity among software developers in recent years [4]. The problem exists when these organizations have sensitive data that they want to use with Git in an unsecure environment. To secure an environment, especially over the internet, involves high levels of cost. As the name implies, GV2 provides Git with a Virtual Vault in a remote location, such as on an Amazon Cloud, using their Amazon S3 storage service. GV2 provides new documented functionality and performance to the research community. This is new research that has high interest from the Department of Defense and other organizations who want to run applications using a third party cloud service provider but also want to maintain confidentiality and integrity of their application data. In the future, many traditional applications will be modified to support this same type of security in an unsecure environment in an efficient manner that is transparent to the user.
I still really want to see this solved. But it needs to be secure, easy to use, and clean... it'll take some effort.
But where's the code?