‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. meinersbur · · focus · HN ↗
    Linus Torvalds in 2007:

    > but the point is the SHA-1, as far as Git is concerned, isn't even a security feature. It's purely a consistency check. The security parts are elsewhere, so a lot of people assume that since Git uses SHA-1 and SHA-1 is used for cryptographically secure stuff, they think that, Okay, it's a huge security feature. It has nothing at all to do with security, it's just the best hash you can get. ... [1]

    [1] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=4XpnKHJAok8&amp;t=56m20s" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=4XpnKHJAok8&amp;t=56m20s

    So Torvalds used SHA-1 purely because he needed a hash function with no other property than identifying content.

    1. creata · · focus · HN ↗
      &gt; It&#x27;s purely a consistency check. The security parts are elsewhere

      Sorry if the video answers this, but how does commit signing work if it doesn&#x27;t rely on the hash algorithm being resistant to at least second-preimage attacks?

      1. someonebaggy · · focus · HN ↗
        Things changed since 2007
        1. xeyownt · · focus · HN ↗
          How they changed?

          For all practical purpose SHA-1 is a bad hash function, it&#x27;s slow, it&#x27;s insecure.

          If SHA-1 is not a security measure, why do you even sign the commit. It doesn&#x27;t make any sense. You give a strong signature on something weak.

          1. someonebaggy · · focus · HN ↗
            Well they didn&#x27;t sign commits in 2007, and there wasn&#x27;t github in 2007, so it wasn&#x27;t a security measure in 2007.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.