‹ BackHN Continuity

Thread

Looking forward to Git 2.56 – and 3.0

207 points · 116 comments · chmaynard

  1. KolmogorovComp · · focus · HN ↗
    Does it mean that when switching trop sha1 to sha256 you need to forcepush and rewrite all history? Wouldn’t that be a massive source of potential vulnerabilities?
    1. nomel · · focus · HN ↗
      I don't know much about this. How does that enable vulnerabilities exactly?
      1. jayd16 · · focus · HN ↗
        Trusting a forced push w/o any other verification means nefarious history changes can be slipped in.
        1. vlovich123 · · focus · HN ↗
          You can still verify the contents - the content blobs don’t change after the migration. Not sure if there’s a practical attack one could do but maybe
          1. awesome_dude · · focus · HN ↗
            Um. how do you verify the contents? The history is for the contents you now have, not what might have been
            1. vlovich123 · · focus · HN ↗
              The contents of the files don’t change, only the Merkle tree. You can verify that the content blobs all have the same sha1 by literally rehashing. Then you can verify that the contents of the clone are the same. That doesn’t stop history corruption, but it does prevent malicious injection into the current state of the tree before the migration.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.