arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Git 提交签名的数月研究

A Multi-Month Study of Git Commit Signing

Abubakar Sadiq Shittu, John Sadik, Scott Ruoti

arXiv 2608.29283首次发表:更新:

发表机构

University of Tennessee , Knoxville(田纳西大学诺克斯维尔分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究对22名计算机科学专业学生开展三个月Git提交签名使用研究,发现其存在配置阻碍、难发现异常提交、对签名保障存误解等问题,指出仅简化签名不足以保障安全使用,还需配套工具与教育支持。

AI 中文摘要

Git 提交签名于2012年推出,是软件供应链中确立提交来源的一种机制,但开发者主动采用该机制的情况仍然罕见,且开发者使用它的体验尚未得到充分研究。为探究这一体验,我们开展了一项为期三个月的研究,研究对象为22名计算机科学专业的高年级本科生和研究生,将他们作为初级开发者的替代样本。参与者需自主配置提交签名,在四个课程项目中使用该功能,将其扩展到第二台设备,检查包含异常提交的外部仓库,并回答与安全推理相关的提示问题。我们发现,尽管几乎所有参与者都成功对每一次提交进行了签名,并对常规签名给出了正面评价,但许多人在设置、多设备配置和仓库验证过程中遇到了阻碍。尽管整个学期都在进行签名操作,他们在验证过程中仍难以发现异常提交,超过四分之一的参与者未发现任何异常。此外,近一半的参与者对签名保障或密钥管理存在至少一个误解。在未明确这些困难是源于工具、教育还是理解层面的情况下,我们得出结论:仅让签名更便捷并不足以确保其安全有效使用。相反,安全采用还需要工具和教育,以支持针对授权身份的签名验证、对缺失签名和未知密钥的解读,以及对密钥生命周期操作的正确推理。

英文摘要

Git commit signing, introduced in 2012, is one mechanism for establishing commit provenance in software supply chains, yet developer-controlled adoption remains rare and developers' experiences using it are understudied. To examine this experience, we conducted a three-month study with senior undergraduate and graduate computer science students (n = 22), whom we treat as proxies for junior developers. Participants configured commit signing independently, used it across four coursework projects, extended it to a second device, examined an external repository containing anomalous commits, and answered security-reasoning prompts. We found that while almost all participants successfully signed every commit and rated routine signing positively, many faced friction during setup, multi-device configuration, and repository verification. Despite signing all semester, they struggled to spot anomalous commits during verification, with over a quarter finding none. Additionally, nearly half expressed at least one misconception regarding signing guarantees or key management. Without isolating whether these difficulties stemmed from tooling, education, or understanding, we conclude that making signing easier is not enough to ensure effective security use. Rather, secure adoption also requires tools and education that support signature verification against authorized identities, interpretation of missing signatures and unknown keys, and correct reasoning about key-lifecycle operations.

CommentsA shortened version of this paper appears in the Proceedings of the 2026 ACM SIGSAC Conference on Computer and Communications Security (ACM CCS 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑