‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. quotemstr · · focus · HN ↗
    Would the author feel the same if git had used MD5 instead of SHA-1?
    1. happytoexplain · · focus · HN ↗
      They address this very theoretical. In short: Yes. Which makes sense if you don't treat the hash as a form of security against malice, especially in the case of attacks that are already impractical, which is the entire thrust of the article.
    2. [deleted] · · focus · HN ↗

      [deleted]

    3. schacon · · focus · HN ↗
      I do actually literally write in this that if it was MD5 it also would not be a problem.
      1. quotemstr · · focus · HN ↗
        Fair cop.
    4. techjamie · · focus · HN ↗
      The hash isn't the security, the distribution is.

      <a href="https:&#x2F;&#x2F;lore.kernel.org&#x2F;git&#x2F;Pine.LNX.4.58.0504291221250.18901@ppc970.osdl.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;lore.kernel.org&#x2F;git&#x2F;Pine.LNX.4.58.0504291221250.1890...

      As linked by another commenter in this thread, Linus worked out years ago that even if someone inserted a malicious object into the kernel repo, it would at best be a nuisance and not a major concern.

    5. eviks · · focus · HN ↗
      Follow the ethos of the quote master!

      &gt; We could be using MD5 and it would honestly probably be just fine.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.