Git 3.0's upcoming SHA-256 default will be a costly mistake
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Git 3.0's upcoming SHA-256 default will be a costly mistake
Unofficial Hacker News client; not affiliated with Y Combinator.
ltbarcly3 · · focus · HN ↗
The alternative to making sha256 the default is to leave sha1 the default. Nobody changes to sha256. sha1 is broken in 10 years. Suddenly everyone has to switch all at once on the same day because it is a critical security issue, but github never implemented sha256 because they didn't have to. This would be a major problem.
This is very very easy to fix if you run into it.
1. Adopt git 3.0 if you can with sha256.
2. If you can't use sha256, set the config to put things back to sha1. Wherever you need to do this you probably already set dozens of ENV vars or settings, just add a new one.
Or write a 15 page analysis about how the above is so hard people will probably just find it catastrophic to even think about.
schacon · · focus · HN ↗
ltbarcly3 · · focus · HN ↗
schacon · · focus · HN ↗
ltbarcly3 · · focus · HN ↗
addaon · · focus · HN ↗
Who is "you" in the context of a distributed version control system? I think this is not just the plural you, but the unbounded you -- it's all people who not just interact with your project now, but who you hope may interact with it in the future. The question is what the cost is of committing a near-infinite population to this migration, not the cost of doing a single `brew update` on your personal machine, no?
ltbarcly3 · · focus · HN ↗
bityard · · focus · HN ↗
OutOfHere · · focus · HN ↗
bigstrat2003 · · focus · HN ↗
pixelesque · · focus · HN ↗
Because a lot of work was done to prepare and fix potential issues.
OutOfHere · · focus · HN ↗
rswail · · focus · HN ↗
If there was an interruption to services on that night in particular, that's a serious public safety issue.
We had tested our system, and integration tested with all the other systems we connected to directly, but any FMECA analysis would show you that there were failure modes that we couldn't mitigate.
So people on planes falling out of the sky? Probably no.
People being crushed in a railway station on NYE? Possible yes.
wavemode · · focus · HN ↗
If you read the OP article, the entire point he's making is that this would never happen, because a hash algorithm being "broken" doesn't matter in practice, because true supply chain security has nothing to do with file hashes.
iamnothere · · focus · HN ↗
That said, it’s still a good idea to migrate to a more robust hashing algorithm. Defense in depth, etc. Just because it’s a difficult migration doesn’t mean it shouldn’t be done.