5 ms·
Following the tradition of sports, I propose that commit id e83c5163316f89bfbde7d9ab23ca2e25604af290 be officially retired.
by byteCoder 12y ago
Following the tradition of sports, I propose that commit id e83c5163316f89bfbde7d9ab23ca2e25604af290 be officially retired.
- SwellJoe 12y agoEvery commit id is pretty much automatically retired. The odds of collisions in our lifetime are pretty small. Or am I over-thinking it?
- traek 12y agoYeah, I'm pretty sure it was a joke.
- VieElm 12y agoI was under the impression that git hashes are generated based on the contents in a commit. If that's true you cannot retire them. They're not random.
- Iburinoc 12y agoWhile that is true, part of the contents that is hashed is the time of commit. Therefore if you (somehow...) managed to get that hash, you could just reset and commit again. Or amend. In any case, I believe he was joking. The odds of a sha1 collision are very very low.
- sytelus 12y agoVery low indeed. Chance of SHA1 collision is of the order of 2^52. One person explained it this way: Chance of everyone currently on Earth winning a jackpot in their lifetime is actually higher than a single random SHA1 collision. It should be actually mind boggling how many of the software systems and algorithms rely on hashes and them being not collided.
- yuhong 12y agoI think it is 2^61 now, the paper that once showed the 2^52 attack has removed the claims.
- CUViper 12y agoGiven that the only way to reuse it is to duplicate the tree and commit metadata exactly, or find an sha1 collision, I think it's pretty safe. :) I wonder if there are any git sha1 collisions out there in aggregate, say across all of github. Would they even notice if there were?
- meowface 12y ago>I wonder if there are any git sha1 collisions out there in aggregate, say across all of github. Despite the incredibly high number of all commits there must be, I think the chance of a collision is still very unlikely. 2^160 is a pretty big number.
- gpvos 12y agoToo bad he didn't use SHA-256 though. It had been available for three years at that moment.
- MichaelGG 12y agoThe number of inputs before a likely collision is more on the order of 2^80. Which is still pretty large.
- meowface 12y agoTrue, the birthday paradox definitely makes it a lot more likely, but as you say the odds should still be too low.
- thret 12y agoThis is comparable to the number of atoms in the universe. Pretty large! We will never see an accidental collision.
- zxcdw 12y agoNot quite, atoms in the universe is in the range of 10^80, which is a bit less than 2^266. On the other hand, 2^80 is "only" approx. 1.2 * 10^24. Still, good luck colliding with that without big effort.
- 6chars 12y agoDone. Don't ask me how I did it, but you will never see that hash come up again naturally during your lifetime.