Remix.run Logo
▲ 6thbit 9 hours ago

I thought this would be a snark but it's an extremely well put together argument against the "Hashmageddon".

If you're replacing the weakness of SHA-1 just by going to another algorithm, you better be prepared to go to the next one when sha256 collisions happen, and it doesn't sound like git's design would be easy to modify for this type of crypto agility.

I do like their proposal for using signatures to establish trust and allow swapping sha256 for whatever comes next.

▲schacon 8 hours ago | parent | next [-]

Technically, git's design (thanks to very smart people trying to solve this problem like brian and others) is _very_ easy to modify to different hashing algorithms now. A lot of amazing work has gone into this in recent years.

However, it's not a git problem. It's an ecosystem problem. It's that every git repo has to choose one and they're entirely incompatible with each other. That is the cost and the difficulty.

▲UltraSane 2 hours ago | parent [-]

Git should support multiple hashes for commits

▲bawolff 8 hours ago | parent | prev | next [-]

I think there is a question though when that will happen and if it will be in our lifetime. SHA-1 started showing weakness in 2005 (collision in 2^69 instead of expected 2^80. This was later brought down to 2^61 in 2011), the same year git was invented. Nobody has found a similar weakness in SHA-256 as of yet. SHA-256 is still at its design strength of 2^128

It took 20 years to go from vulnerability in sha-1 to having to replace it out of caution. There is no such vuln in sha-256 yet. It could easily be 25 years before we find one, and another 25 years before we have to do something about it. Perhaps longer. Will git still be used 50 years from now?

▲6thbit 8 hours ago | parent [-]

With the kind of compute power available nowadays and AI models I wouldn't be surprised we see it much sooner.

All it takes is just one collision to consider it broken right?

But hey maybe the attempt to fix it makes git controversial enough it falls out of favor, and nobody uses it anymore in 2 years, problem solved? sure.

▲bawolff 7 hours ago | parent [-]

> All it takes is just one collision to consider it broken right?

No, its considered broken before that stage. i.e. when someone discovers an attack that would allow someone to create a collision faster than they should while still being impractical.

> With the kind of compute power available nowadays and AI models I wouldn't be surprised we see it much sooner.

Computer power doesn't super matter, what matters is algorithmic breakthroughs. So far i dont think there are any examples of major breakthroughs of that type via AI, although perhaps i am just misinformed. Its still early in the AI revolution, it might still happen, but as it stands i don't think there is any reason to worry about that.

▲TheRealPomax 9 hours ago | parent | prev [-]

Perhaps not clear enough, but Scott was a cofounder of GitHub, so he knows a thing or two about git in the real world =)

▲schacon 8 hours ago | parent [-]

Being a founder of GitHub doesn't make my opinion more interesting. I hope the argument stands no matter who wrote it. :)

▲TheRealPomax 4 hours ago | parent [-]

It does though, even if it shouldn't be blindly taken as gospel. Arguments help, but some folks have a better brand of apple box to stand on, and "I live and breathe git" helps quite a bit ;)