‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. theowaway · · focus · HN ↗
    they could just have taken the sha1 of the sha256.
    1. GrantMoyer · · focus · HN ↗
      Then `git fsck` wouldn't be able to tell if an object uses the sha1 scheme or the sha1∘sha256 scheme, so it may need to compute the both hashes to check an object's integrity. Also, an object name alone wouldn't indicate that the weak scheme shouldn't be used to check integrity, so a malicious sha1 object could be swapped in in place of an sha1∘sha256 object (if second-preimage is found).
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.