‹ BackHN Continuity

Thread

Looking forward to Git 2.56 – and 3.0

207 points · 116 comments · chmaynard

  1. GTP · · focus · HN ↗
    Why not transitioning to SHA3 directly? IIRC lenght extension attacks are not currently feasible on SHA2, but still theoretically possible.
    1. cesarb · · focus · HN ↗
      Length extension attacks are not an issue for git, because every object has two fields in its header, which is prepended to the object before hashing: the object type and the length in bytes.
      1. GTP · · focus · HN ↗
        Interesting. Anyway, since they're going through the pain of changing the hash function, why not using the latest standard? SHA3 has been standardized for some time now, and using SHA256 isn't any easier than using SHA3-256.
        1. adastra22 · · focus · HN ↗
          SHA3 does not supersede SHA2. They are different types of hashes useful for different purposes.
          1. GTP · · focus · HN ↗
            While SHA2 and SHA3 use very different algorithms, the purpose of the SHA standard stays the same. Or maybe I'm missing some official document from NIST saying otherwise that you could point me to?
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.