| ▲ | amluto 7 hours ago | |
> "[a] tree's cryptographic strength is equal to the weakest hash algorithm anywhere in the tree" This is simply wrong IMO, for two reasons: 1. The attack on SHA-1 is a collision attack. Once you have frozen a hash, you cannot attack it with existing cryptanalysis. If there were a preimage attack it would be a different story. 2. Even if there were preimage attacks, one could freeze a mapping from SHA1 hash to SHA-256 hash. In fact, #2 seems like en excellent design. Objects could reference such a mapping, and a repo could disallow conflicting mappings (the mappings would only be accepted if the mapped objects are reachable from the mapping and the mapping is correct). | ||