Git's Trust Model is Broken
Why Git's identity model is insecure, how easy commit spoofing is and how to fix it with commit signing. Explains the risks, demonstrates real-world spoofing and provides a step-by-step solution for securing your commits.
If you want to read more about boring technology, check out the linked article.