‹ BackHN Continuity

Thread

Looking forward to Git 2.56 – and 3.0

207 points · 116 comments · chmaynard

  1. TacticalCoder · · focus · HN ↗
    So Git, in version 3.0, is moving to SHA-256 by default for SHA-1 ain't considered that strong anymore but...

    What about future attacks by quantum computers? Is Git safe from quantum computers for it's all hashes only? Or shall there be issues with quantum attacks?

    I'm asking for there are several projects that are already moving to quantum-resistant schemes (like OpenSSH who uses an hybrid scheme [1]).

    [1] <a href="https:&#x2F;&#x2F;www.openssh.org&#x2F;pq.html" rel="nofollow">https:&#x2F;&#x2F;www.openssh.org&#x2F;pq.html

    1. krior · · focus · HN ↗
      But their post-quantum-algorithm also uses sha256. Afaik only asymetric crypto is in danger from quantum computers.
      1. TacticalCoder · · focus · HN ↗
        Ah it&#x27;s interesting, AIUI cryptographic hashes are safe from quantum attacks (for there&#x27;s an infinity of secrets that, once hashed, give a specific hash and hence somehow it&#x27;s not possible to use a quantum computer to forge what you&#x27;d want).

        And from the other comment, symmetric cryptography is safe too from QC attacks.

        So it&#x27;s apparently as you wrote: it&#x27;s really only asymmetric crypto that is at risk.

        1. jcranmer · · focus · HN ↗
          &gt; AIUI cryptographic hashes are safe from quantum attacks (for there&#x27;s an infinity of secrets that, once hashed, give a specific hash and hence somehow it&#x27;s not possible to use a quantum computer to forge what you&#x27;d want).

          Quantum algorithms require some sort of quantum &#x27;trick&#x27; to actually have any speedup over classical computers. The most general quantum trick is Grover&#x27;s algorithm, which lets you find f⁻¹(x) (given f and x) in sqrt(N) queries rather than N queries, where N is the size of the set from which x is drawn. This cuts the bit security of every algorithm in half, although for things like cryptographic hashes, it really means that a second preimage is now only as &#x27;easy&#x27; as finding a collision (due to the birthday attack).

          The other really well-known quantum trick is QFT, which allows you to find the period of an unknown periodic function really quickly. This is what allows quantum computers to break asymmetric algorithms based on integer factoring or elliptic curves, since they can both be expressed in terms of the QFT.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.