| ▲ | schacon 9 hours ago | |||||||||||||||||||||||||||||||||||||||||||
1) I link to the SHAttered paper, as well as Shambles. Git projects were not affected because it is an inefficient attack vector. I say it's impractical to exploit, which I think everyone agrees with. 2) I specifically argue that even if both attacks were practical and cheap, it's still not the problem we should be focusing on. 3) Have you read this email (that I linked to)? It is almost the same general message (20 years ago) that this blog post is. It literally goes though a theoretical object replacement attack and how dumb this scenario is and so SHA-1 is fine. https://lore.kernel.org/git/Pine.LNX.4.58.0504291221250.1890... | ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | bawolff 8 hours ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||||||||
> 1) I link to the SHAttered paper, as well as Shambles. Git projects were not affected because it is an inefficient attack vector. I say it's impractical to exploit, which I think everyone agrees with. It seems unlikely it will stay that way forever. Typically attacks get more efficient over time as researchers find improvements, not to mention computers getting better. In 2015 it was estimated to cost $100,000, now the estimate is down to $10,000. Where will it be in 2035? | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | kpcyrd 7 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||||||||
Basing your cryptographic advice on a 20 year old opinion-piece from somebody with no background in cryptography is not the flex you think it is. | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||