‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. nicoburns · · focus · HN ↗
    From what I'd read, SHA256 in git is showing every sign of being another IPv6. In particular:

    - It's implemented in a non-backwards-compatible way

    - The benefits over the older model are a bit nebulous

    - There's a large amount of tooling that needs to catch up, and little sign that there is movement there

    1. Onavo · · focus · HN ↗
      There's a massive push right now from top down to have secure software supply chains. Google SBOM and SigStore. It's not an organic need but if you have government customers you don't have many options.
      1. Dayshine · · focus · HN ↗
        Ironically rewriting git history is a perfect opportunity for a supply chain attack.
        1. samus · · focus · HN ↗
          The switchover date is usually announced well in advance and any interested parties can easily verify that the conversion was authentic.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.