4 ms·
All of which is why Fossil now uses SHA3-256 by default. How long is it going to take Git to follow?
by wyoung2 4y ago
All of which is why Fossil now uses SHA3-256 by default.
How long is it going to take Git to follow?
- tasuki 4y agoHave hash collisions in Git ever been a problem for you? What is the exact scenario in which a hash collision would be dangerous? (Like, you give some random person push access to your repository and... I'm really getting lost here... they override some commit with a different commit with the same hash? And that's somehow worse than them just creating a new commit with a different hash, which you would notice for sure? And the only reason you won't notice their Evil Change is because they sneaked it in inside a hash collision?)
- wyoung2 4y agoWe don't know how to push bad artifacts into a Merkle tree by exploiting SHA-1's weaknesses. The thing is, though, we didn't want to be pushed into scrambling for a better hash algorithm after some clever bastard works that trick out. :)
- yjftsjthsd-h 4y agoIt appears that git currently has experimental, non-backward-compatible support for sha256, so I'd guess "as soon as they finish fixing any issues and figure out a nice upgrade path", with the caveat that there's little pressure because it's not actually a practical problem yet and isn't expected to be one in the foreseeable future.
- wyoung2 4y agoFossil's method is backwards-compatible, and we published the method for it five years ago (2017-03-05): https://fossil-scm.org/home/doc/trunk/www/hashpolicy.wiki https://fossil-scm.org/home/doc/trunk/www/hashpolicy.wiki