‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. quotemstr · · focus · HN ↗
    Would the author feel the same if git had used MD5 instead of SHA-1?
    1. techjamie · · focus · HN ↗
      The hash isn't the security, the distribution is.

      <a href="https:&#x2F;&#x2F;lore.kernel.org&#x2F;git&#x2F;Pine.LNX.4.58.0504291221250.18901@ppc970.osdl.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;lore.kernel.org&#x2F;git&#x2F;Pine.LNX.4.58.0504291221250.1890...

      As linked by another commenter in this thread, Linus worked out years ago that even if someone inserted a malicious object into the kernel repo, it would at best be a nuisance and not a major concern.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.