‹ BackHN Continuity

Thread

Looking forward to Git 2.56 – and 3.0

207 points · 116 comments · chmaynard

  1. KolmogorovComp · · focus · HN ↗
    Does it mean that when switching trop sha1 to sha256 you need to forcepush and rewrite all history? Wouldn’t that be a massive source of potential vulnerabilities?
    1. nomel · · focus · HN ↗
      I don't know much about this. How does that enable vulnerabilities exactly?
      1. jayd16 · · focus · HN ↗
        Trusting a forced push w/o any other verification means nefarious history changes can be slipped in.
        1. wtfwhateven · · focus · HN ↗
          Semi-relevant-ish: <a href="https:&#x2F;&#x2F;blog.citp.princeton.edu&#x2F;2013&#x2F;10&#x2F;09&#x2F;the-linux-backdoor-attempt-of-2003&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.citp.princeton.edu&#x2F;2013&#x2F;10&#x2F;09&#x2F;the-linux-backdoo...
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.