| ▲ | quotemstr 9 hours ago | |||||||
Would the author feel the same if git had used MD5 instead of SHA-1? | ||||||||
| ▲ | eviks 19 minutes ago | parent | next [-] | |||||||
Follow the ethos of the quote master! > We could be using MD5 and it would honestly probably be just fine. | ||||||||
| ▲ | schacon 9 hours ago | parent | prev | next [-] | |||||||
I do actually literally write in this that if it was MD5 it also would not be a problem. | ||||||||
| ||||||||
| ▲ | happytoexplain 9 hours ago | parent | prev | next [-] | |||||||
They address this very theoretical. In short: Yes. Which makes sense if you don't treat the hash as a form of security against malice, especially in the case of attacks that are already impractical, which is the entire thrust of the article. | ||||||||
| ▲ | techjamie 8 hours ago | parent | prev | next [-] | |||||||
The hash isn't the security, the distribution is. https://lore.kernel.org/git/Pine.LNX.4.58.0504291221250.1890... As linked by another commenter in this thread, Linus worked out years ago that even if someone inserted a malicious object into the kernel repo, it would at best be a nuisance and not a major concern. | ||||||||
| ▲ | 9 hours ago | parent | prev [-] | |||||||
| [deleted] | ||||||||