3 ms·
> Linus just doesn't take this stuff seriously. I really wish he would, though. Can't downvote this enough. This is plain FUD. Did you even read the complete t
by simplehuman 10y ago
> Linus just doesn't take this stuff seriously. I really wish he would, though.
Can't downvote this enough. This is plain FUD. Did you even read the complete thread on the git mailing list? This was just one proposal by him.
- AgentME 10y agoIf he took this stuff seriously, he wouldn't have waited 12 years since SHA-1 was broken to even start considering any changes.
- simplehuman 10y agoSo did anyone on this thread send patched to the mailing list? Obviously you guys are very serious right?
- aseipp 10y agoThis conversation has gone on several times over the course of years on the Git mailing list. In almost every situation it's been completely brushed off as a mostly non-issue to change from SHA-1 inside Git, despite the fact it's been known SHA-1 has basically been on life support. There are lots of opinions on both sides, but ultimately, until now, the Upstream decision seemed to be "WONTFIX". Given this context, of course nobody wrote patches: they would have obviously been rejected and been a total waste of time. Until now, when we actually have to deal with it. This is all aside from your argument being fundamentally weak, however ("you can't criticize anything unless i say so and contributed by meeting this arbitrary standards. i mean, didn't do anything either, i just get to make up the rules you abide by!!")
- simplehuman 10y ago> This is all aside from your argument being fundamentally weak, however ("you can't criticize anything unless i say so and contributed by meeting this arbitrary standards. i mean, didn't do anything either, i just get to make up the rules you abide by!!") Are we both reading the same GP comment? It reads as "If he took this stuff seriously, he wouldn't have waited 12 years since SHA-1 was broken to even start considering any changes.".
- nickpsecurity 10y agoIt's equivalent to the other comments. The others just have more facts to back it up & should've probably been the original. If The reason it's equivalent is: 1. Saw a known issue that cryptographers and security people were warning him about. 2. Alternatives existed that didn't have that issue. People were pushing on it. 3. Ignored all that to tell them it wasn't a problem, the issue could never have real-world consequences, and he wasn't interested in fixes. In practice, that means he didn't take it seriously. He also made sure it wouldn't get fixed by letting people know he wasn't making a change to it. One more example in a long line of them where Linus doesn't give a shit about security enough to apply known, good practices.
- AgentME 10y agoLinus ranted[0] about how it's idiotic to worry about SHA-1 collisions in 2005 months after significant weaknesses[1] were found in it (which have recently been demonstrated by Google). I'm certainly not about to waste effort making a patch that he's going to reject as idiotic. [0] http://www.gelato.unsw.edu.au/archives/git/0504/0885.html http://www.gelato.unsw.edu.au/archives/git/0504/0885.html [1] https://www.schneier.com/blog/archives/2005/02/sha1_broken.html https://www.schneier.com/blog/archives/2005/02/sha1_broken.h...