Remix.run Logo
▲ ltbarcly3 9 hours ago

This seems like Y2K fud.

The alternative to making sha256 the default is to leave sha1 the default. Nobody changes to sha256. sha1 is broken in 10 years. Suddenly everyone has to switch all at once on the same day because it is a critical security issue, but github never implemented sha256 because they didn't have to. This would be a major problem.

This is very very easy to fix if you run into it.

1. Adopt git 3.0 if you can with sha256.

2. If you can't use sha256, set the config to put things back to sha1. Wherever you need to do this you probably already set dozens of ENV vars or settings, just add a new one.

Or write a 15 page analysis about how the above is so hard people will probably just find it catastrophic to even think about.

▲wavemode 9 hours ago | parent | next [-]

> sha1 is broken in 10 years. Suddenly everyone has to switch all at once on the same day because it is a critical security issue

If you read the OP article, the entire point he's making is that this would never happen, because a hash algorithm being "broken" doesn't matter in practice, because true supply chain security has nothing to do with file hashes.

▲bityard 9 hours ago | parent | prev | next [-]

It's easy for _one person_ to fix. It's not easy for the entire git ecosystem as a whole. GitHub, large internal corporate git repos, CI/CD systems, projects with submodules, etc. The second half the article explains all of this.

▲iamnothere 9 hours ago | parent | prev | next [-]

It’s already broken, but even though it’s broken it’s hard to generate git collisions because of the repo metadata. It’s easy to generate (for instance) standalone PDFs with identical hashes, but doing this with git in a useful way is much harder.

That said, it’s still a good idea to migrate to a more robust hashing algorithm. Defense in depth, etc. Just because it’s a difficult migration doesn’t mean it shouldn’t be done.

▲schacon 9 hours ago | parent | prev | next [-]

You can certainly do this, as I said, this is Google's backup plan. But defaults matter. People will start running this and getting repos that are uselessly incompatible with other repos, tools, libraries and server instances. Having it as an option is one thing. Making it a default will cause a lot of pain for people who don't want to care about this.

▲ltbarcly3 9 hours ago | parent [-]

"defaults matter" is an argument for this change, not against it.

▲schacon 9 hours ago | parent [-]

No, my argument is that the change should not happen at all and nobody wants it and it gains the community very, very little but the default change is forcing it on everyone and most will be _entirely_ unaware - now having to solve problems that are difficult to understand. Defaults also matter when they are the wrong defaults.

▲ltbarcly3 9 hours ago | parent [-]

This is not difficult to understand. It's very easy to understand.

▲addaon 9 hours ago | parent | prev | next [-]

> Adopt git 3.0 if you can with sha256.

Who is "you" in the context of a distributed version control system? I think this is not just the plural you, but the unbounded you -- it's all people who not just interact with your project now, but who you hope may interact with it in the future. The question is what the cost is of committing a near-infinite population to this migration, not the cost of doing a single `brew update` on your personal machine, no?

▲ltbarcly3 9 hours ago | parent [-]

Just clone the repo again. Jesus Christ, you act like the simplest thing in the world is some kind of insurmountable challenge.

▲OutOfHere 9 hours ago | parent | prev [-]

For the record, Y2K was not fud. It was very real, in a long list of datetime problems that are to come. Further datetime problems are coming at scheduled dates.

▲bigstrat2003 9 hours ago | parent [-]

It was definitely FUD. There was a real problem (date counters would roll over), but the impacts of it were so ridiculously overstated that it eclipsed any sane discussion of the issue. We had people at the time predicting that planes would literally fall out of the sky when Y2k hit, which was never a realistic possibility.

▲pixelesque 9 hours ago | parent | next [-]

> which was never a realistic possibility.

Because a lot of work was done to prepare and fix potential issues.

▲OutOfHere 7 hours ago | parent | prev [-]

That's the problem with deniers. When responsible persons take preemptive action to prevent tragedy, like with Y2K, the diners say it was FUD. When people don't take action, like with climate change, they say it wasn't important considering it's not them who's dead, totally discounting those who have suffered or died as a consequence. In summary, the deniers are so incompetent that they can't be trusted to correctly maintain a car, let alone civilization, considering they would never even the replace the necessary parts at the right schedules in their car.