| ▲ | singpolyma3 an hour ago | |
signatures are basically always computed over hashes. The only problem here is that the hashes are not secure. And this is being fixed. | ||
| ▲ | kazinator 33 minutes ago | parent [-] | |
No, but, the hashes are features of the content tracking system that hook it together. There is no reason that a signing scheme must rely on and trust those hashes! We can round up the bits that make up a commit in a SHA-1-based repo, and sign those bits securely; this is a thing that is possible. | ||