‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. 0x00cl · · focus · HN ↗
    I think this change is more to do with politics rather than "security". Those kind of things where companies or gov, need to be certified with those super secure certificates and can't be using software that uses SHA-1. I don't have proof, but I'm not doubting it either.

    This is what I saw in one of the mails. > > There are organizations where SHA-1 is blanket banned across the board - regardless of its use

    And also on git 3.0 breaking changes. > > SHA-1 ... recommended against in FIPS 140-2 and similar certifications

    Since SHA-1 isn't used for security in git, they should've instead moved to a non-cryptographic hash function such as MurmurHash3 and avoid all these problems, instead of moving to SHA-256 until SHA-256 is broken and need to move to the next cryptographic hash that is now incompatible with previous versions of git repositories.

    1. artyom · · focus · HN ↗
      > There are organizations where SHA-1 is blanket banned across the board

      This is very likely the case. And if it is, then it's a lost battle. You simply can't reason with that kind of corporate people, let alone have an argument around this level of complexity. Kafka (the writer, not the message broker) predicted this 100 years ago.

      When going through the article, my instinct was changing from "annoying" to "this really sounds like a Python 2/3 moment for Git" to finally "oof this is going to be a mess" in the libraries/submodules part.

      1. someonebaggy · · focus · HN ↗
        Meanwhile they are looking at us and thinking "you simply can't reason with programmers, they insist on using broken encryption"
        1. artyom · · focus · HN ↗
          Haha that's funny even if it's not accurate.

          In my experience corporate box checkers don't care about reasoning (much less "encryption") at all, they see it as an annoying blocker in their path to the next promotion.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.