4 ms·
Thank you for pointing this out, and thank you for the link the the relevant code section. Excellent comment.
by Zamicol 4y ago
Thank you for pointing this out, and thank you for the link the the relevant code section. Excellent comment.
- omegalulw 4y agoLmao how were you that confident in your original comment which basically claimed git signatures are only as secure as SHA-1.
- brasic 4y agoPerhaps you misinterpreted my reply. I didn’t intend to dispute parent’s claim, merely to correct a mechanical detail. Git signatures are more or less only as secure as SHA-1, although the properties it relies on are not yet compromised and several factors mitigate the real-world risk. A practical preimage attack on SHA-1 would seriously undermine the security of git signatures since the string being signed includes two or more SHA-1 hashes representing a content snapshot and the commit ancestry. Arbitrary preimage attacks would make it possible to modify a repo’s contents or history without invalidating oids or signatures. In practice only collision attacks have been found, all of which have a detectable signature that git has been modified to detect. Disclosure: I work at GitHub, but am speaking for myself.