- Home
- Search Results
- Page 1 of 1
Search for: All records
-
Total Resources2
- Resource Type
-
0002000000000000
- More
- Availability
-
02
- Author / Contributor
- Filter by Author / Creator
-
-
Fahl, Sascha (2)
-
Klemmer, Jan H (2)
-
Burton, Cordell (1)
-
Busch, Niklas (1)
-
Fischer, Fabian (1)
-
Fourné, Marcel (1)
-
Friedrich, Kay (1)
-
Holtgrave, Jan-Ulrich (1)
-
Horstmann, Stefan Albert (1)
-
Huaman, Nicolas (1)
-
Lipford, Heather Richter (1)
-
Ludden, Cordelia (1)
-
Massacci, Fabio (1)
-
Naiakshina, Alena (1)
-
Patnaik, Nikhil (1)
-
Powers, Carson (1)
-
Rahman, Akond (1)
-
Rashid, Awais (1)
-
Votipka, Daniel (1)
-
Wermke, Dominik (1)
-
- Filter by Editor
-
-
& Spizer, S. M. (0)
-
& . Spizer, S. (0)
-
& Ahn, J. (0)
-
& Bateiha, S. (0)
-
& Bosch, N. (0)
-
& Brennan K. (0)
-
& Brennan, K. (0)
-
& Chen, B. (0)
-
& Chen, Bodong (0)
-
& Drown, S. (0)
-
& Ferretti, F. (0)
-
& Higgins, A. (0)
-
& J. Peters (0)
-
& Kali, Y. (0)
-
& Ruiz-Arias, P.M. (0)
-
& S. Spitzer (0)
-
& Sahin. I. (0)
-
& Spitzer, S. (0)
-
& Spitzer, S.M. (0)
-
(submitted - in Review for IEEE ICASSP-2024) (0)
-
-
Have feedback or suggestions for a way to improve these results?
!
Note: When clicking on a Digital Object Identifier (DOI) number, you will be taken to an external site maintained by the publisher.
Some full text articles may not yet be available without a charge during the embargo (administrative interval).
What is a DOI Number?
Some links on this page may take you to non-federal websites. Their policies may differ from this site.
-
Critical open-source projects form the basis of many large software systems. They provide trusted and extensible implementations of important functionality for cryptography, compatibility, and security. Verifying commit authorship authenticity in open-source projects is essential and challenging. Git users can freely configure author details such as names and email addresses. Platforms like GitHub use such information to generate profile links to user accounts. We demonstrate three attack scenarios malicious actors can use to manipulate projects and profiles on GitHub to appear trustworthy. We designed a mixed-research study to assess the effect on critical open-source software projects and evaluated countermeasures. First, we conducted a large-scale measurement among 50,328 critical open-source projects on GitHub and demonstrated that contribution workflows can be abused in 85.9% of the projects. We identified 573,043 email addresses that a malicious actor can claim to hijack historic contributions and improve the trustworthiness of their accounts. When looking at commit signing as a countermeasure, we found that the majority of users (95.4%) never signed a commit, and for the majority of projects (72.1%), no commit was ever signed. In contrast, only 2.0% of the users signed all their commits, and for 0.2% of the projects all commits were signed. Commit signing is not associated with projects’ programming languages, topics, or other security measures. Second, we analyzed online security advice to explore the awareness of contributor spoofing and identify recommended countermeasures. Most documents exhibit awareness of the simple spoofing technique via Git commits but no awareness of problems with GitHub’s handling of email addresses.more » « lessFree, publicly-accessible full text available January 1, 2026
-
Klemmer, Jan H; Horstmann, Stefan Albert; Patnaik, Nikhil; Ludden, Cordelia; Burton, Cordell; Powers, Carson; Massacci, Fabio; Rahman, Akond; Votipka, Daniel; Lipford, Heather Richter; et al (, ACM)Free, publicly-accessible full text available December 2, 2025
An official website of the United States government
