4 ms·
It's important to note that a malicious organization could always backdate revisions, and force push over the github repository.
by JacobHenner 11y ago
It's important to note that a malicious organization could always backdate revisions, and force push over the github repository.
- jdminhbg 11y agoNot with matching SHAs though, so someone dedicated to tracking changes would know.
- startling 11y agoGit's hashing is not cryptographically secure.
- arjunnarayan 11y agoAll it takes is a single person having it cloned, who can call them out because the hash values would have changed. This isn't really a realistic threat.
- gcr 11y agoThat single person who cloned it could also backdate their hashes and claim things changed when they didn't.