[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

git and https



While we're on the subject of git security...should we stop recommending that non-account-holders use git:// (most efficient, but insecure against MITM unless you manually check the commit number) in preference to https:// (at least some security)? https://wiki.debian.org/Alioth/Git#Accessing_repositories

Any suggestions for persuading upstreams to care about these issues? Mine has no https on the repository (though they do on the release tarballs), no signed anything, and have not responded to me pointing out that this is a security hole: https://bugs.freedesktop.org/show_bug.cgi?id=89682


Reply to: