Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hn_p4ttern
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
hn_p4ttern
3y ago
> "I believe there is one more step. You have to somehow get the collision into the repository." Yes, Exactly. So, is it necessary to change SHA-1 having in git ? At the moment, I think there is no reason because SHA-1 doesn&#x
2.
▲
by
hn_p4ttern
3y ago
> "For now the SHA-1 collisions are easily detectable, but it could get worse." Your opinion: prove it! And Again, if you instead of trolling actually read the post in THIS BRANCH , the question is: shout SHA-1 inn GIT be subst
3.
▲
by
hn_p4ttern
3y ago
My point is: why you should change hashing algorithm in GIT ??? Let's elaborate: 1. Do SHA-1 put a security risk in GIT ? 2. Is that practically exploitable in any way? In some application, for example password hashing, SSH MAC, etc, y
4.
▲
by
hn_p4ttern
3y ago
1) We are talking about sha1, md5 is out of topic 2) This is the main topic ! Being able to generate >>valid code<< with a >>specific purpose<< , so that GIT have to change its hashing algorithm; 3) A.K.A your answer
5.
▲
by
hn_p4ttern
3y ago
IMHO "be padded into a comment" is included in "is valid code", still 1 in <number_of_particles_in_universe_here^1E100> is a good approximation of that probability. Please, correct me if I'm wrong.
6.
▲
by
hn_p4ttern
3y ago
Is it used to sign a commit, right ? Which are the probabilities to have a collision that: a) is still code b) is still code AND is code similar to a previous commit c) is still code AND is code similar to a previous commit AND is valid d)