| ▲ | theowaway 8 hours ago | |
they could just have taken the sha1 of the sha256. | ||
| ▲ | GrantMoyer 2 hours ago | parent [-] | |
Then `git fsck` wouldn't be able to tell if an object uses the sha1 scheme or the sha1∘sha256 scheme, so it may need to compute the both hashes to check an object's integrity. Also, an object name alone wouldn't indicate that the weak scheme shouldn't be used to check integrity, so a malicious sha1 object could be swapped in in place of an sha1∘sha256 object (if second-preimage is found). | ||