‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. ltbarcly3 · · focus · HN ↗
    This seems like Y2K fud.

    The alternative to making sha256 the default is to leave sha1 the default. Nobody changes to sha256. sha1 is broken in 10 years. Suddenly everyone has to switch all at once on the same day because it is a critical security issue, but github never implemented sha256 because they didn't have to. This would be a major problem.

    This is very very easy to fix if you run into it.

    1. Adopt git 3.0 if you can with sha256.

    2. If you can't use sha256, set the config to put things back to sha1. Wherever you need to do this you probably already set dozens of ENV vars or settings, just add a new one.

    Or write a 15 page analysis about how the above is so hard people will probably just find it catastrophic to even think about.

    1. schacon · · focus · HN ↗
      You can certainly do this, as I said, this is Google's backup plan. But defaults matter. People will start running this and getting repos that are uselessly incompatible with other repos, tools, libraries and server instances. Having it as an option is one thing. Making it a default will cause a lot of pain for people who don't want to care about this.
      1. ltbarcly3 · · focus · HN ↗
        "defaults matter" is an argument for this change, not against it.
        1. schacon · · focus · HN ↗
          No, my argument is that the change should not happen at all and nobody wants it and it gains the community very, very little but the default change is forcing it on everyone and most will be _entirely_ unaware - now having to solve problems that are difficult to understand. Defaults also matter when they are the wrong defaults.
          1. ltbarcly3 · · focus · HN ↗
            This is not difficult to understand. It's very easy to understand.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.