‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. 6thbit · · focus · HN ↗
    I thought this would be a snark but it's an extremely well put together argument against the "Hashmageddon".

    If you're replacing the weakness of SHA-1 just by going to another algorithm, you better be prepared to go to the next one when sha256 collisions happen, and it doesn't sound like git's design would be easy to modify for this type of crypto agility.

    I do like their proposal for using signatures to establish trust and allow swapping sha256 for whatever comes next.

    1. schacon · · focus · HN ↗
      Technically, git's design (thanks to very smart people trying to solve this problem like brian and others) is _very_ easy to modify to different hashing algorithms now. A lot of amazing work has gone into this in recent years.

      However, it's not a git problem. It's an ecosystem problem. It's that every git repo has to choose one and they're entirely incompatible with each other. That is the cost and the difficulty.

      1. UltraSane · · focus · HN ↗
        Git should support multiple hashes for commits
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.