4 ms·
Doesn't their change break supply chain security on Google's end? With git tags, presumably people spoke in terms of cryptographic hashes. Now what prevents t
by hedora 2mo ago
Doesn't their change break supply chain security on Google's end?
With git tags, presumably people spoke in terms of cryptographic hashes. Now what prevents them from serving different Google drive contents to different accounts?
- CBLT 2mo agoIt doesn't break supply chain security for anybody with power to change the situation.
- asdfsa32 2mo agoIt is an easy to overlook this, but even for someone in position of power to change, creating different code with the same hash is borderline impossible.
- CBLT 2mo agoNon-sequitor? They're not providing a (sha-1) hash, they're providing source code to integration partners using their business channels, not public git providers. Those business channels include contracts etc to "secure their supply chain". You and I aren't in those business channels, and we're not being given anything with a hash. There's simply no hash to collide with?
- asdfsa32 2mo agoA git hash is cryptographically secure. It doesn't matter how you distribute it. That is the entire point you're missing.
- deleted 2mo ago[deleted]