3 ms·
On git moving away from SHA1: it's about time. - There shouldn't be too many nor too few hash algos. Too many: paradox of choice, user confusion and interop o
by ReligiousFlames 9y ago
On git moving away from SHA1: it's about time.
- There shouldn't be too many nor too few hash algos. Too many: paradox of choice, user confusion and interop overhead. Too few: security monoculture risks being broken by well-funded state actors
- Sane, future-ready default: SHA3-512
Also, git GPG signing should change to signing content, in addition to or instead of, hashes.
- adrianN 9y agoIsn't signing a hash the standard procedure for signatures?
- dozzie 9y agoThe thing is, you are signing hash of a hash of data instead of simply hash of data.
- lgas 9y agoWhat would be the benefit of signing content instead of hashes?
- rurban 9y agoThe benefit would be to trust the content, and not the hash of the content. Esp. with SHA1 being the only hash so far.