‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. benthecarman · · focus · HN ↗
    Core of the issue seems like github UX issues that they can solve
    1. hedora · · focus · HN ↗
      In fairness, there's a second issue: Git repos should just support multiple hashes, so you could just add SHA-256 to a SHA-1 repo, which would then transparently support both SHAs.

      This even would make the SHA-1 git objects collision resistant when stored on a trusted server, even with untrusted clients. (Exercise left to the reader.)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.