Remix.run Logo
▲ quotemstr 9 hours ago

Would the author feel the same if git had used MD5 instead of SHA-1?

▲eviks 19 minutes ago | parent | next [-]

Follow the ethos of the quote master!

> We could be using MD5 and it would honestly probably be just fine.

▲schacon 9 hours ago | parent | prev | next [-]

I do actually literally write in this that if it was MD5 it also would not be a problem.

▲quotemstr 9 hours ago | parent [-]

Fair cop.

▲happytoexplain 9 hours ago | parent | prev | next [-]

They address this very theoretical. In short: Yes. Which makes sense if you don't treat the hash as a form of security against malice, especially in the case of attacks that are already impractical, which is the entire thrust of the article.

▲techjamie 8 hours ago | parent | prev | next [-]

The hash isn't the security, the distribution is.

https://lore.kernel.org/git/Pine.LNX.4.58.0504291221250.1890...

As linked by another commenter in this thread, Linus worked out years ago that even if someone inserted a malicious object into the kernel repo, it would at best be a nuisance and not a major concern.

▲ 9 hours ago | parent | prev [-]
[deleted]