5 ms·
> It is simply NOT TRUE that you can generate an object that looks halfway sane and still gets you the sha1 you want This was his point, and it's still true. G
by btym 10y ago
> It is simply NOT TRUE that you can generate an object that looks halfway sane and still gets you the sha1 you want
This was his point, and it's still true. Generating a specific SHA-1 hash is still not feasible.
- euyyn 10y agoIt's not so inconceivable, after seeing the PDF collision, to contribute to another project a commit whose hash has a collision with another malicious commit you keep up your sleeve. Not saying it's easy, but now it's on the horizon.
- otabdeveloper 10y ago> Not saying it's easy, but now it's on the horizon. Not really. It's not a preimage attack. They spent several hundred dollars to find two random byte strings with the same SHA1 hash. There's still no way to SHA1-collide a specific byte string instead of random junk.
- victorNicollet 10y agoThis is exactly what euyyn is saying: create two files with the same SHA1 (by adding bytes of gibberish to an unused section), commit one to the repository, and now you have an collision available.
- mi100hael 10y agoThat's not how git uses hashes. In that scenario, there would still be a diff and hence git would recognize the files were different.