‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. meinersbur · · focus · HN ↗
    Linus Torvalds in 2007:

    > but the point is the SHA-1, as far as Git is concerned, isn't even a security feature. It's purely a consistency check. The security parts are elsewhere, so a lot of people assume that since Git uses SHA-1 and SHA-1 is used for cryptographically secure stuff, they think that, Okay, it's a huge security feature. It has nothing at all to do with security, it's just the best hash you can get. ... [1]

    [1] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=4XpnKHJAok8&amp;t=56m20s" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=4XpnKHJAok8&amp;t=56m20s

    So Torvalds used SHA-1 purely because he needed a hash function with no other property than identifying content.

    1. zamalek · · focus · HN ↗
      Exactly. But that&#x27;s why I think SHA was a mistake. He should have gone with something like murmur to avoid all this frothing at the mouth.
      1. layer8 · · focus · HN ↗
        It was a mistake to assume a fixed algorithm in the repository format and client-server protocol. I remember being surprised when I learned about that choice, being familiar with cryptographic protocols and formats where the hash algorithm is usually a parameter that can vary for each concrete hash.
        1. throw0101c · · focus · HN ↗
          &gt; It was a mistake to assume a fixed algorithm in the repository format and client-server protocol.

          See also perhaps Wireguard, which touts itself as not having &quot;cryptographic agility&quot; because they wanted to avoid all (perceived) problems and complications of IPsec. But now that PQC is (allegedly) approaching there&#x27;s no easy to update things because (AIUI) there&#x27;s no negotiation possible in the protocol; you&#x27;re basically standing up a &#x27;Wireguard 2.0&#x27; that runs separately than the original.

          1. computerfriend · · focus · HN ↗
            Wireguard is secure against a quantum computer though, via an additional pre-shared key.

            &gt; If an additional layer of symmetric-key crypto is required (for, say, post-quantum resistance), WireGuard also supports an optional pre-shared key that is mixed into the public key cryptography.

            (From <a href="https:&#x2F;&#x2F;www.wireguard.com&#x2F;protocol&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wireguard.com&#x2F;protocol&#x2F;.)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.