‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. purpleidea · · focus · HN ↗
    This means, if you migrate your repo, every single commit message that contains text like: "please see commit <sha1>" will now be broken.

    This will be a train wreck. I hope they don't release before adding compatibility modes to keep the existing sha1's around in the database.

    1. windsurfer · · focus · HN ↗
      Since SHA-1 is already broken (just expensive in terms of GPU-time), then the text "please see commit <sha1>" is also already broken.
      1. Dylan16807 · · focus · HN ↗
        You can't attack an existing normal commit.

        But also collisions there aren't a big deal. People will cite short hashes when referring to things and that's not "broken".

        1. windsurfer · · focus · HN ↗
          If it's an existing commit and you're already converting the repo, you can just convert the commit messages as well.
      2. schacon · · focus · HN ↗
        That is essentially only a second preimage problem, which is basically impossible.
        1. [deleted] · · focus · HN ↗

          [deleted]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.