‹ BackHN Continuity

Thread

Git 3.0's upcoming SHA-256 default will be a costly mistake

570 points · 536 comments · chmaynard

  1. gandreani · · focus · HN ↗
    One of my favorite fun facts about Fossil SCM (another source control by the devs of sqlite) is that they patched their use of SHA1 6 days after the shattered attack was published:

    "Both Fossil and Git started out using only SHA1 hashes. But when the SHAttered attack against SHA1 was published on 2017-02-23, the need to migrate to a stronger hash algorithm was recognized. Fossil added the ability to use SHA3-256 as an alternative on 2017-03-01 (six days after the SHAttered attack was first published). SHA3-256 is now the default for all new repositories and check-ins in Fossil, though older check-ins that occurred prior to SHAttered can still use their original SHA1 hash. Hence, no repositories had to be rebuilt and no hyperlinks were broken."

    <a href="https:&#x2F;&#x2F;fossil-scm.org&#x2F;home&#x2F;doc&#x2F;trunk&#x2F;www&#x2F;hundredandone.md" rel="nofollow">https:&#x2F;&#x2F;fossil-scm.org&#x2F;home&#x2F;doc&#x2F;trunk&#x2F;www&#x2F;hundredandone.md

    To me it&#x27;s so interesting watching in realtime Git is still battling with this decision and for Fossil it was just another week of development.

    That whole page is fun to read. Another fun fact somewhere else in the docs is that Fossil uses a grow-only set to store commits. They came up with this scheme some years before it was formalized by CRDTs!

    1. somat · · focus · HN ↗
      I always liked the ipfs concept of a multihash where a hash algorithm id is stored with the hash, I don&#x27;t know how well it worked in practice, but in theory all applications of the protocol are now forced into a world where there are multiple hash formats and it can and will change.
      1. jmyeet · · focus · HN ↗
        We don&#x27;t need that. Introducing an unknown hash algorithm itself is a security issue.

        This problem isn&#x27;t hard or new. Just look at things like a TLS handshake. You need to separate the protocol from the storage implementation.

        I personally believe the initial Git programmers were too in love with the efficiency of doing a bitwise 160 bit comparison on the stack and they sacrificed the known issue of changing the algorithm to do it. A decade earlier the same thing had happened with MD5.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.