3 ms·
Truncating the sha256 hashes does sound like a reasonable intermediate step and should also enable interoperability (a guess from my side - if it is only about
by phkx 4y ago
Truncating the sha256 hashes does sound like a reasonable intermediate step and should also enable interoperability (a guess from my side - if it is only about referencing objects, it probably does not matter how the keys were generated).
At some point one could then transition to the full hashes and make the truncated ones an option.
I‘m wondering what tooling is heavily dependent on the length of the hashes. Potentially if you want to keep the size of the transmitted data small (at work, we once considered git as a versioned database for an IoT use case…).
- TedDoesntTalk 4y agoYou could SHA-1 hash the SHA-256 hash instead of truncating it :)
- mlindner 4y agoI mean that doesn't help anything as if you collide the SHA-1 hash you automatically get a SHA-256 hash collision.
- awestroke 4y agoThat can't be true
- mlindner 4y agoPerhaps I misinterpreted your comment. If you have X and Y such that X has a SHA1 hash collision with Y, you end up such that SHA256(SHA1(X)) == SHA256(SHA1(Y)). That's why I said what I said.
- nequo 4y agoI think the ancestor comment meant SHA1(SHA256(X)) instead. Not clear to me how that wouldn’t have collisions, too. Just that the underlying commits that generate the collisions would need to look different.
- mlindner 4y agoIf that's the case you can just replace the SHA256(X) portion with arbitrary content to get the above SHA1 collision.
- gregmac 4y agoI don't follow. If the algorithm is SHA1(SHA256(X)) all an attacker can modify is X. Yes it's possible to find a SHA1() collision, but finding X where the SHA256() will generate a collision -- that is SHA1(SHA256(X)) == SHA1(SHA256(Y)) -- is still required. The question is does the SHA1 step make this any easier? Don't you still have to either break SHA256 (predicting the hash it will generate) or do this by brute force?
- mlindner 4y agoI was assuming that it was optionally SHA1(X) or SHA1(SHA256(X)) with the determination of which happening being something attacker controllable in X.
- TedDoesntTalk 4y agoI’m OP. I mean SHA1(SHA256(X)) but I have no idea if that makes a collision more difficult than SHA1(X) or any other implications. It was a way to reduce to hash length without truncation.
- ilyt 4y agoI'd imagine it's easy error to make to just go and load sha1 length of characters from git, or splattering some validation in code going "okay this is not sha1-length hash, must be something wrong with data"