‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. sigmar · · focus · HN ↗
    >it will be an incomprehensibly expensive and ultimately valueless and avoidable global nightmare.

    thought "costly" in the title and "incomprehensibly expensive" in the subheader meant this piece would discuss how much less performant sha-256 is on modern machines, but didn't see anything. isn't there hardware acceleration? how much worse is it?

    1. schacon · · focus · HN ↗
      Actually, I think sha-256 is possibly faster than the sha1dc variant that Git currently uses.

      I just sent a patch series to the list that enables sha1dc to be accelerated on modern CPU architectures to close to normal SHA1 speeds, but since it was ported from a Rust project by an agent, it will never be applied.

      <a href="https:&#x2F;&#x2F;lore.kernel.org&#x2F;git&#x2F;20260929112544.86511-1-scott@gitbutler.net&#x2F;" rel="nofollow">https:&#x2F;&#x2F;lore.kernel.org&#x2F;git&#x2F;20260929112544.86511-1-scott@git...

      1. hedora · · focus · HN ↗
        Last I checked SHA-256 was faster than SHA-1, and SHA-512 was even faster (though the output is annoyingly long).
        1. debugnik · · focus · HN ↗
          How could SHA-512 be faster? It does more rounds of the exact same operations as SHA-256 with a bigger state. Although if it really were faster, SHA-512&#x2F;256 gives you a truncated version.
          1. adrian_b · · focus · HN ↗
            It hashes a double amount of data per cycle with much less than a double amount of operations.

            SHA-512 is always faster in software than SHA-256, when run on 64-bit CPUs, and it is also faster in the CPUs that support both SHA-256 and SHA-512 in hardware.

            Arm-based CPUs have supported SHA-512 already for many years and the latest Intel CPUs also support it, i.e. Lunar Lake, Arrow Lake S (S is for desktops, Arrow Lake H for laptops does not support it), Panther Lake and Clearwater Forest.

            I expect that AMD Zen 6 should also support it, because they are the last important vendor without SHA-512 support.

            All modern CPUs support SHA-256 in hardware, so it is faster when SHA-512 is not supported in hardware, otherwise SHA-512&#x2F;256 is preferable, by being both faster and more secure.

            1. debugnik · · focus · HN ↗
              Thanks, that makes sense. I was vaguely aware that SHA-256 halved the internal state from SHA-512 but not that it halved the block size, I haven&#x27;t looked much into it. Although it makes sense in retrospect that they would simply use 32-bit variables to keep the same structure.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.