NDSS 2025 – Rethinking Trust In Forge-Based Git Security
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。我得先仔细看看这篇文章的内容。 文章标题是“Rethinking Trust In Forge-Based Git Security”,作者们来自纽约大学和新泽西理工学院。他们提出了一个叫做gittuf的系统,目的是去中心化Git的安全性。现在GitHub这样的平台作为受信任的第三方,但缺乏开放协议来证明它们的可信度,这可能带来风险。 gittuf系统有三个主要功能:分散政策声明和管理责任,分散活动跟踪,以及分散政策执行。这样可以避免单点故障,比如当中心化平台被攻破时,还能保证安全。此外,它还能防止未经授权的分支和标签更改。 文章还提到gittuf在大型项目中的表现不错,存储开销不到4%,验证时间不到0.59秒。这意味着它不仅安全,而且高效。 所以总结起来,这篇文章主要介绍了gittuf系统如何通过去中心化来增强Git的安全性,并且在实际应用中表现良好。 </think> 文章介绍了一种名为gittuf的新系统,该系统通过去中心化方式增强Git版本控制系统安全性,使每个用户都能参与保障仓库安全,分散政策管理、活动跟踪和执行责任,防止单点故障,并有效保护代码免受未授权更改,适用于大型项目。 2026-1-22 16:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Session 9D: Github + OSN Security

Authors, Creators & Presenters: Aditya Sirish A Yelgundhalli (New York University), Patrick Zielinski (New York University), Reza Curtmola (New Jersey Institute of Technology), Justin Cappos (New York University)
PAPER
Rethinking Trust In Forge-Based Git Security
Git is the most popular version control system today, with Git forges such as GitHub, GitLab, and Bitbucket used to add functionality. Significantly, these forges are used to enforce security controls. However, due to the lack of an open protocol for ensuring a repository’s integrity, forges cannot prove themselves to be trustworthy, and have to carry the responsibility of being non-verifiable trusted third parties in modern software supply chains. In this paper, we present gittuf, a system that decentralizes Git security and enables every user to contribute to collectively enforcing the repository’s security. First, gittuf enables distributing of policy declaration and management responsibilities among more parties such that no single user is trusted entirely or unilaterally. Second, gittuf decentralizes the tracking of repository activity, ensuring that a single entity cannot manipulate repository events. Third, gittuf decentralizes policy enforcement by enabling all developers to independently verify the policy, eliminating the single point of trust placed in the forge as the only arbiter for whether a change in the repository is authorized. Thus, gittuf can provide strong security guarantees in the event of a compromise of the centralized forge, the underlying infrastructure, or a subset of privileged developers trusted to set policy. gittuf also implements policy features that can protect against unauthorized changes to branches and tags i.e., pushes as well as files/folders i.e., commits. Our analysis of gittuf shows that its properties and policy features provide protections against previously seen version control system attacks. In addition, our evaluation of gittuf shows it is viable even for large repositories with a high volume of activity such as those of Git and Kubernetes (less than 4% storage overhead and under 0.59s of time to verify each push).
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.

Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations’ YouTube Channel.

Permalink

*** This is a Security Bloggers Network syndicated blog from Infosecurity.US authored by Marc Handelman. Read the original post at: https://www.youtube-nocookie.com/embed/FA1gEAKJAR0?si=LoEUi5pvl3MpJADw


文章来源: https://securityboulevard.com/2026/01/ndss-2025-rethinking-trust-in-forge-based-git-security/
如有侵权请联系:admin#unsafe.sh