2 ms·
There is some speculation on whether Linus got it right or wrong, but I haven't seen anyone actually test this with the shattered-1 & 2 files, so I did. Git se
by phaemon 10y ago
There is some speculation on whether Linus got it right or wrong, but I haven't seen anyone actually test this with the shattered-1 & 2 files, so I did.
Git sees them as different despite them having the same hash. You can test with:
mkdir shattered && cd shattered
git init
wget https://shattered.it/static/shattered-1.pdf
git add shattered-1.pdf
git commit -am "First shattered pdf"
git status
wget https://shattered.it/static/shattered-2.pdf
sha1sum *
md5sum *
mv shattered-2.pdf shattered-1.pdf
git status
So it doesn't see the files the same.
Apologies for those on mobile (please fix this HN!): the commands are:
mkdir shattered && cd shattered
&& git init
&& wget https://shattered.it/static/shattered-1.pdf https://shattered.it/static/shattered-1.pdf
&& git add shattered-1.pdf
&& git commit -am "First shattered pdf"
&& git status
&& wget https://shattered.it/static/shattered-2.pdf https://shattered.it/static/shattered-2.pdf
&& sha1sum *
&& md5sum *
&& mv shattered-2.pdf shattered-1.pdf
&& git status
EDIT: Ah, of course! git adds a header and takes the sha1sum of the header+content, which breaks the identical SHA1 trick. You can add a footer on and they keep the same SHA1 though. Don't have time to play about with this more just now, but try it with `cat`ing some identical headers and footers onto the pdfs.
EDIT2: Actually, this is discussed more extensively in the other thread which I hadn't read yet. Go there for more details: https://news.ycombinator.com/item?id=13713480 https://news.ycombinator.com/item?id=13713480