In a well-fleshed-out post, Scott Chacon shows how unneecessary Git 3.0's move to replace SHA-1 with SHA-256 is.

you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 1 week ago (3 children)

There's people who seriously think commit hashes are there for security purposes? Furthermore, there are git MAINTAINERS that think this?

How absurd. Author is completely right, making SHA-256 the default implementation serves no purpose. SHA-1 is a completely valid algorithm for non-security use cases, which is precisely how git uses it. This is a solution looking for a problem.

I think he's maybe overblowing the impact of this change. Realistically, the only ones who are going to be impacted are the folks who maintain git-related tools and forges, as he mentions. The rest of us probably won't even notice. But that's still a ton of pointless work for those folks.

  • source
  • hideshow 3 child comments
  • [–] 1 point 6 days ago

    I think he's maybe overblowing the impact of this change.

    Maybe... But I don't look forward to working with the dozens of IT folks at my company who all installed git once and have never upgraded. This will be multiple meetings, show up on slide decks, break builds...

    It's going to be a right pain for nothing.

  • source
  • parent
  • [–] 0 points 6 days ago* (1 child)

    Wait, they don't affect security? Wouldn't a hash collision mean pulling that hash from GitHub would pull wrong code? Or maybe delete code? I'd assume the hash is used as a lookup key in a database somewhere.

    You also pin dependencies to specific hashes for security reasons.

  • source
  • parent
  • hideshow 1 child comment