kornel,
@kornel@mastodon.social avatar

I've set up git commit signing with SSH. It was relatively easy, and did not need any GPG cruft.

https://calebhearth.com/sign-git-with-ssh

krinkle,
@krinkle@fosstodon.org avatar

deleted_by_author

  • Loading...
  • matt,

    @kornel You might want to read this post by @glyph questioning whether signing commits, and more generally unquestioned complexity in the name of security, is a good idea: https://blog.glyph.im/2024/01/unsigned-commits.html

    glyph,
    @glyph@mastodon.social avatar

    @matt @kornel Thanks Matt! I should also stress that this is a piece you kinda need to read all the way through. A few people have come away from reading the headline with the idea that I just don't like git commit signing specifically and they should turn it off as opposed to turning it on. For some people, in some situations, it makes perfect sense and it's a fine security primitive. To quote one of the last paragraphs of the blog:

    > Git commit signing itself is not particularly consequential

    brokenix,

    @kornel actually you can have gpg agent work for SSH too and it works on my system

    kornel,
    @kornel@mastodon.social avatar

    @brokenix That would ruin both git and SSH for me. To me not using GPG in any shape or form is the goal.

    bjfs84,
    @bjfs84@vivaldi.net avatar

    @kornel @brokenix Sir, explain why GPG is bad, you can provide links =)

    Frankly I'm aware that SSH signing is the new cool for Git verified commits.

    kornel,
    @kornel@mastodon.social avatar

    @bjfs84 As a protocol it's full of outdated weak cryptography, without a clear path to migrate away from it, so even modern reimplementations bring back the broken algorithms for compatibility. From tooling perspective, gpg is overcomplicated with dangerously bad defaults, and shoddy integrations. Its use in e-mail is hopelessly unfixably terrible. While it could be just used as a key format, that needlessly pulls in all of the complexity and old cruft for the failed features.

    kornel,
    @kornel@mastodon.social avatar
    bjfs84,
    @bjfs84@vivaldi.net avatar

    @kornel fair enough, I remember one company having https://www.passwordstore.org as their secret storage solution. Oh my, it was a menace trying to sign every new user, often breaking the chain for others xD

    GnuPG, with all sentiment to FSF. Feels like a legacy product...

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • mdbf
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • Youngstown
  • everett
  • anitta
  • slotface
  • GTA5RPClips
  • rosin
  • thenastyranch
  • kavyap
  • tacticalgear
  • modclub
  • JUstTest
  • osvaldo12
  • Durango
  • khanakhh
  • provamag3
  • cisconetworking
  • ngwrru68w68
  • cubers
  • tester
  • ethstaker
  • megavids
  • normalnudes
  • Leos
  • lostlight
  • All magazines