‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. flowerthoughts · · focus · HN ↗
    Oh, agreed this sounds like a terrible migration path and shouldn't really be needed in the first place.

    What I'm missing in the article is whether any Git server accepts replacing a SHA-1 identified object it already has. If it doesn't, then the distribution trust discussed holds, and keeping SHA-1 seems fine. Adding additional signatures seems fine for those who need transitive trust.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.