5 ms·
Its possible to go in and replace the hash algorithm with something else, which none of these "git is going to ruin everything with not replacing SHA1 this inst
by RubyPinch 10y ago
Its possible to go in and replace the hash algorithm with something else, which none of these "git is going to ruin everything with not replacing SHA1 this instant!" people seem to bother with, to prove their points, instead of endless posturing.
http://stackoverflow.com/a/34599081 http://stackoverflow.com/a/34599081 has actually gone about doing it, but it has been over a year since that, and as linus says, there has been multiple collision mitigations added as well, so tests should probably be re-done
- hvidgaard 10y agoYou can, but they should reengineer Git to use any hash function, and not assume output length.
- mattkrause 10y agoI think the bigger problem is that tons of other stuff also assumes the output length.
- hvidgaard 10y agoThat can be mitegated, but the sooner steps are made towards changing it, the easier it will be.
- CJefferson 10y agoMy git with different hash would be useless. It wouldn't be able to interact with github, bitbucket, or pull/push to anyone else's repositories. I may as well rename the package. Fixing this is going to require breaking backwards compatability with every program that works with git -- it's going to be a huge undertaking, because early in git's design they didn't support multiple hash functions.
- RubyPinch 10y agoTo clarify, I mean to replace the hash with something that would collide far more often, to simulate collisions, to see how git handles them
- CJefferson 10y agoAh, that is a much more sensible request! Sorry for my harsh reply.
- robin__j 10y agohttps://stackoverflow.com/a/34599081 https://stackoverflow.com/a/34599081 In this SO answer does it by reducing the hash size from 160-bit to 4-bit.