3 ms·
Signing git commits is broken anyway as you are basically signing the commit hash (which is a sha1, whose collision resistance is broken).
by dependenttypes 6y ago
Signing git commits is broken anyway as you are basically signing the commit hash (which is a sha1, whose collision resistance is broken).
- cordite 6y agoI recall hearing github is planning on Sha-256 some time
- some_furry 6y agoThey're more likely to employ counter-cryptanalysis [1] in the meantime. [1] https://github.com/cr-marcstevens/sha1collisiondetection https://github.com/cr-marcstevens/sha1collisiondetection