3 ms·
If you are capable of inserting this kind of backdoor, how easy is it to compromise a version control system? (or the login details of one of the programmers?).
by StringyBob 11y ago
If you are capable of inserting this kind of backdoor, how easy is it to compromise a version control system? (or the login details of one of the programmers?).
Is it possible to prevent history of the code being modified? Do DVCS use blockchains?
- hueving 11y agoIf a git commit is modified, every commit hash after it will change and will break every clone.
- deleted 11y ago[deleted]
- wosos 11y agoTrue, it could've been easier to use fake credentials from the start
- escape_goat 11y agoThat's a system that would still be entirely vulnerable to collision attacks, though, right?
- vishbar 11y agoI'd imagine it would be nearly impossible to generate a collision that a.) does what you want, b.) is small enough to be unobtrusive, and c.) can be discovered in finite time with the computing power reasonably available to NSA/GCHQ/insert SIGINT organization of choice.
- escape_goat 11y agoI asked because git uses SHA1, which might be a bit low on (c) at this point.
- vishbar 11y agoTrue. Generating collisions is doable, but a.) and b.) are still huge constraints that make it orders of magnitude more difficult.