Remix.run Logo
▲ schacon 9 hours ago

1) I link to the SHAttered paper, as well as Shambles. Git projects were not affected because it is an inefficient attack vector. I say it's impractical to exploit, which I think everyone agrees with.

2) I specifically argue that even if both attacks were practical and cheap, it's still not the problem we should be focusing on.

3) Have you read this email (that I linked to)? It is almost the same general message (20 years ago) that this blog post is. It literally goes though a theoretical object replacement attack and how dumb this scenario is and so SHA-1 is fine.

https://lore.kernel.org/git/Pine.LNX.4.58.0504291221250.1890...

▲bawolff 8 hours ago | parent | next [-]

> 1) I link to the SHAttered paper, as well as Shambles. Git projects were not affected because it is an inefficient attack vector. I say it's impractical to exploit, which I think everyone agrees with.

It seems unlikely it will stay that way forever. Typically attacks get more efficient over time as researchers find improvements, not to mention computers getting better.

In 2015 it was estimated to cost $100,000, now the estimate is down to $10,000. Where will it be in 2035?

▲schacon 8 hours ago | parent | next [-]

I specifically argue that it doesn't matter if it's $1 and base my argument and solution around that. So it's irrelevant where it is in 2035.

▲bawolff 7 hours ago | parent [-]

You still mentioned the (1) part, which is what i object to. I agree its not fatal to your argument.

▲AlfeG 7 hours ago | parent | prev [-]

Even if it costs zero to create. How do You force people to pull from Your repo?

▲axus 7 hours ago | parent | next [-]

Hack into the system holding a trusted repository, and swap in your variant with same signature?

▲maccam94 2 hours ago | parent | prev | next [-]

DNS cache poisoning?

▲patmorgan23 3 hours ago | parent | prev [-]

Social engineering?

▲kpcyrd 7 hours ago | parent | prev [-]

Basing your cryptographic advice on a 20 year old opinion-piece from somebody with no background in cryptography is not the flex you think it is.

▲wavemode 3 hours ago | parent | next [-]

Appealing to lack-of-authority without actually explaining in what way his argument is wrong is significantly worse.

▲throwawayffffas an hour ago | parent | prev | next [-]

It's not cryptographic advice from an opinion piece, it's a statement about intent from the creator of the software in question.

▲PunchyHamster 3 hours ago | parent | prev [-]

But the Linus piece is sound

... for Linux

... and developers working for it constantly

the attack wouldn't work. Joe Schmoe? It's worse than just "being compromised"

You have repo of dependency locally, let's assume you downloaded good copy, the commits get compromised, you're safe.... right ?

Nope, if there is build server along the way and ESPECIALLY if it practices building from clean state every time, the build might be infected while your local copy is clean, giving no chance to notice it, unless your entire chain including local builds are reproductible AND you actually check it