New research from Carnegie Mellon shows any signed GitHub commit can be copied into a second commit with identical metadata and code, a valid signature, and a "Verified" badge without the author's secret key.
This breaks the promise that each commit ID is a unique fingerprint. An attacker can re-issue the same signed code under a fresh verified ID, bypassing blocks or pinning. Git and GitHub have not fixed it.
https://www.internationalcyberdigest.com/new-research-a-verified-github-commit-is-not-unique
#security #github #programming
This breaks the promise that each commit ID is a unique fingerprint. An attacker can re-issue the same signed code under a fresh verified ID, bypassing blocks or pinning. Git and GitHub have not fixed it.
https://www.internationalcyberdigest.com/new-research-a-verified-github-commit-is-not-unique
#security #github #programming
1