4 ms·
I agree SHA-1 is a poor choice for signing git objects, for reasons that should have been obvious when it was implemented. Unfortunately I don't think the same
by _jjkk 6y ago
I agree SHA-1 is a poor choice for signing git objects, for reasons that should have been obvious when it was implemented.
Unfortunately I don't think the same developers who are assuming all hashes have some kind of magic security properties, are the ones who would follow your best practice for default choice of hash functions.
Also I wish some of those higher throughput hashes were available in e.g. python's hashlib by default. For applications that can include minimal or no external packages, hashlib.sha1 still turns out to be the best choice in certain cases.