4 ms·
I hope this has nothing to do with the people who hacked sourceforge..
by ericmsimons 16y ago
I hope this has nothing to do with the people who hacked sourceforge..
- jrockway 16y agoGit has full cryptographic history (and data) authentication, so any changes to the history would be easily detectable. And you can sign known-good commits, so that even if you've never pulled before, you can still verify the part of the history that's been signed. SVN and CVS are missing this key feature, which is why the sf.net hacking is scary.
- ericmsimons 16y agoI'm a Git n00b, so thanks for pointing that out! No wonder git has killed off SVN
- oomkiller 16y agoIt hasn't yet, but it is making great headway, and I for one can't wait!
- saurik 16y agoGit's hashing detects data corruption to an existing user, but to someone who hasn't downloaded the repository yet and is getting it for the first time you really have to remember that SHA1 is currently considered "broken". It is increasingly feasible for someone to generate a collision to an existing file, allowing them to forge a commit. This has been discussed on the git mailing list, for the record, and the response is generally "don't care, we don't claim this to be a security mechanism". This is even a problem if you use signed tags, as you are only signing the result of a broken hash function.