‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. MBCook · · focus · HN ↗
    So they’ve been talking about this for many years, planning, and finally announce when they’re going to switch the default.

    So this is the right time to post that everything they’re doing is wrong? Did you engage in all the discussions about it and how best to handle it? Whether SHA-256 was the best solution?

    I don’t see anywhere that it talks about alternate proposals or why they might have been better. Why the particular suggestions here were rejected.

    This seems like a bunch of Monday morning quarterbacking.

    1. kazinator · · focus · HN ↗
      A number of years ago when I heard about this, I was pretty angry and made a private fork of git immediately in which I tried to scrub away the SHA-256 bullshit. But that's basically just paddling upstream with a spoon for a oar.

      The stewards of Git are going to do whatever they want, and there is nothing you can do about it if you don't have the clout to create a fork that takes the lead.

      No amount of discussion will do anything because they've already decided that their view of the situation is correct. Git hashes are not just content identification but a digital certificate mechanism, and their collision resistance is a grave issue that must be fixed, the end.

      You will be browbeaten in any discussion; it's not worth the energy in a world replete with issues.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.