4 ms·
SHA-1 was already known to be broken at the time Git chose it, but they chose it anyway. Choosing a non-broken algorithm like SHA-2 was an easy choice they coul
by AgentME 4y ago
SHA-1 was already known to be broken at the time Git chose it, but they chose it anyway. Choosing a non-broken algorithm like SHA-2 was an easy choice they could have made that would still hold up today. Implementing a crypto agility system is not without major trade-offs (consider how common downgrade attacks have been across protocols!).
- fishywang 4y ago>SHA-1 was already known to be broken at the time Git chose it Please pardon my ignorance but could you elaborate on what time (e.g. the year) are you referring to?
- LarryMullins 4y agoSince about 2005, collision attacks against SHA-1 have been known. In 2005 Linus dismissed these concerns as impractical, writing: > The basic attack goes like this: > > - I construct two .c files with identical hashes. Ok, I have a better plan. - you learn to fly by flapping your arms fast enough - you then learn to pee burning gasoline - then, you fly around New York, setting everybody you see on fire, until people make you emperor. Sounds like a good plan, no? But perhaps slightly impractical. Now, let's go back to your plan. Why do you think your plan is any better than mine? https://git.vger.kernel.narkive.com/9lgv36un/zooko-zooko-com-revctrl-colliding-md5-hashes-of-human-meaningful#post2 https://git.vger.kernel.narkive.com/9lgv36un/zooko-zooko-com...
- chlorion 4y agoThis is a really good example of Torvalds toxic attitude and absolutely horrific attitude towards security. This is an occurring pattern unfortunately. Git not being prepared for this is going to cost a lot of time and money for a very large amount of people, and it could have been trivially mitigated if security were taken seriously in the first place, and if Torvalds was mature enough to understand the he is not an expert on cryptography topics.
- nighthawk454 4y agoI didn't know either. From Wikipedia [1], SHA-1 has been considered insecure to some degree since 2005. Following the citations, apparently it's been known since at least August 2004 [2] but maybe not demonstrated in SHA-1 until early 2005. git's first release was in 2005, so I guess technically SHA-1 issues could've been known or suspected during development time. More generously, it could've been somewhat simultaneous. It sounds like it was considered a state-sponsored level attack at the time, if collisions were even going to be possible. Don't know if the git devs knew this and intentionally chose it anyway, or just didn't know. [1] https://en.wikipedia.org/wiki/SHA-1 https://en.wikipedia.org/wiki/SHA-1 [2] https://www.schneier.com/blog/archives/2005/02/cryptanalysis_o.html https://www.schneier.com/blog/archives/2005/02/cryptanalysis... EDIT: sibling comment has evidence that Linus did in fact know about it and considered it an impractical vector at the time https://git.vger.kernel.narkive.com/9lgv36un/zooko-zooko-com-revctrl-colliding-md5-hashes-of-human-meaningful#post2 https://git.vger.kernel.narkive.com/9lgv36un/zooko-zooko-com...
- groestl 4y ago> Choosing a non-broken algorithm like SHA-2 was an easy choice they could have made that would still hold up today. Yet, the requirement of the hashing algorithm for Git is not broken, it's not cryptographic but merely stochastic, and Linus knows this. Why bother to produce a collision, when you have the power to get your changes pulled into a release branch? Your attack might be noticed, and your cover blown. Instead, simply try to get a bug merged that results in a zero day. In case somebody discovers it, at least you have plausible deniability that it happened on accident.