NDSS 2025 – Rethinking Trust In Forge-Based Git Security
嗯,用户让我用中文总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,找出主要信息。 文章是关于Git安全的,特别是GitHub这样的平台。作者们提出了一个叫做gittuf的系统,旨在去中心化Git的安全机制。他们提到gittuf有三个主要功能:分散政策管理、分散活动跟踪和分散政策执行。这样可以防止单一实体操控仓库事件,增强安全性。 此外,gittuf还能保护分支和标签不受未经授权的更改,并且在大型仓库中表现良好,存储开销不到4%,验证时间不到0.59秒。这些数据说明gittuf不仅安全有效,而且实用性强。 所以总结的时候,我需要涵盖gittuf的核心功能、去中心化的优势以及实际应用中的表现。确保在100字以内清晰传达这些要点。 </think> 文章介绍了一种名为gittuf的系统,通过去中心化方式增强Git版本控制系统安全性。该系统允许所有用户共同管理仓库安全策略、跟踪活动并独立验证授权变更,避免对单一平台或开发者的过度依赖。实验表明,gittuf能有效防止常见攻击,并适用于大型项目(如Git和Kubernetes),具备低存储开销和快速验证能力。 2026-1-22 20:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Session 9D: Github + OSN Security

Authors, Creators & Presenters: Aditya Sirish A Yelgundhalli (New York University), Patrick Zielinski (New York University), Reza Curtmola (New Jersey Institute of Technology), Justin Cappos (New York University)
PAPER
Rethinking Trust In Forge-Based Git Security
Git is the most popular version control system today, with Git forges such as GitHub, GitLab, and Bitbucket used to add functionality. Significantly, these forges are used to enforce security controls. However, due to the lack of an open protocol for ensuring a repository’s integrity, forges cannot prove themselves to be trustworthy, and have to carry the responsibility of being non-verifiable trusted third parties in modern software supply chains. In this paper, we present gittuf, a system that decentralizes Git security and enables every user to contribute to collectively enforcing the repository’s security. First, gittuf enables distributing of policy declaration and management responsibilities among more parties such that no single user is trusted entirely or unilaterally. Second, gittuf decentralizes the tracking of repository activity, ensuring that a single entity cannot manipulate repository events. Third, gittuf decentralizes policy enforcement by enabling all developers to independently verify the policy, eliminating the single point of trust placed in the forge as the only arbiter for whether a change in the repository is authorized. Thus, gittuf can provide strong security guarantees in the event of a compromise of the centralized forge, the underlying infrastructure, or a subset of privileged developers trusted to set policy. gittuf also implements policy features that can protect against unauthorized changes to branches and tags i.e., pushes as well as files/folders i.e., commits. Our analysis of gittuf shows that its properties and policy features provide protections against previously seen version control system attacks. In addition, our evaluation of gittuf shows it is viable even for large repositories with a high volume of activity such as those of Git and Kubernetes (less than 4% storage overhead and under 0.59s of time to verify each push).
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.

Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations’ YouTube Channel.

Permalink

*** This is a Security Bloggers Network syndicated blog from Infosecurity.US authored by Marc Handelman. Read the original post at: https://www.youtube-nocookie.com/embed/FA1gEAKJAR0?si=LoEUi5pvl3MpJADw


文章来源: https://securityboulevard.com/2026/01/ndss-2025-rethinking-trust-in-forge-based-git-security-2/
如有侵权请联系:admin#unsafe.sh