| ▲ | amluto 4 hours ago | |||||||
> I could replace a commit from 2010 with a malicious one How? Remember, there are (currently, anyway) no known SHA-1 preimage attacks. | ||||||||
| ▲ | mort96 3 hours ago | parent [-] | |||||||
We're discussing a hypothetical situation where SHA-1 gets even more broken. From my original comment in this thread (https://news.ycombinator.com/item?id=49924179#49925367): > If I can forge commits with any SHA1 hash at will We probably don't want to wait until there are practical pre-image attacks discovered to change away from SHA-1. | ||||||||
| ||||||||