| ▲ | schacon 9 hours ago | |
I mean, there are two things here. One is how difficult it is to have a different hashing mechanism. Brian and other heroes in the Git core group have done amazing work to make this _technically_ possible on a repo level. To test some of my theories, I trivially implemented MD5 and an insanely dumb and easily breakable hash backend. It's not _hard_ to change the mechanism now. It's about the community. Fossil isn't difficult to change not because it's technically harder for Git but because Git has a community and ecosystem that Fossil does not. The cost is not in the individual project for Git, the cost is because there is _so much_ in Git and this bifurcates everything. | ||
| ▲ | schacon 8 hours ago | parent | next [-] | |
Also, interestingly, Git today does _not_ use a straight SHA1 because of these attacks. It uses `sha1dc`, a slower collision detecting variant that specifically checks for this vector of attacks. So currently, Git's SHA-1 variant is not susceptible to the SHAttered/Shambles attacks. | ||
| ▲ | gandreani 9 hours ago | parent | prev [-] | |
Agreed! This isn't a tech dig at all. To me it's more of a reality of creating a tool with a huge active community and a community of contributors and creating a tool with a small team and small community. | ||