Uploaded image for project: 'Bitbucket Cloud'
  1. Bitbucket Cloud
  2. BCLOUD-18440

Bitbucket Cloud does not match or audit SSH key to user account matches

    XMLWordPrintable

Details

    Description

      Hi,

      Firstly, we already are aware that Bitbucket Cloud makes no attempt to verify local Git config, such as email and username, and simply checks the SSH key connecting has access/permission.

      Consider the 2 following separate situations, which as far as I can tell, are unstoppable and unauditable currently in Bitbucket Cloud. Please correct me if I am wrong about this.

      1. I create a personal user account, set my local git config to match that user, and then push commits to our team repo.
      2. I simply add the email and name of a colleague in the same team, and push commits to our team repo.

      In both these cases, Bitbucket Cloud will show the Author of the commit as the one in the git local config. There is clearly no attempt to check the authors identity has any access, or even has the used SSH key attached (it does not).

      The team audit log does not show any commit history. The commits page in the repository only shows the spoofed information.

      Please tell me how an Enterprise organisation with its own auditing requirements, is supposed to prevent or audit this. Surely I have missed something?

      Attachments

        Activity

          People

            Unassigned Unassigned
            3f8c4eafa838 Jamie Gibbard
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: