Git 3.0 will make SHA-256 the new default content hashing algorithm and it will be an incomprehensibly expensive and ultimately valueless and avoidable global nightmare.
Very interesting. I taught git to students last year and was showing them the SHA256 option and the issues he’s describing was pretty much what I was wondering about. If you force people to switch, with no intercompatibility, holy shit this is gonna be quite the clusterfuck!
What I’m taking away from this is that Linus was right from the get go : SHA1 isn’t there for security, it’s a really good algorithm for a hashtable’s hash where we really want to avoid collisions. That’s it.
If you’re thinking it’s safe because it used to be involved in security, you’re a muppet.
Very interesting. I taught git to students last year and was showing them the SHA256 option and the issues he’s describing was pretty much what I was wondering about. If you force people to switch, with no intercompatibility, holy shit this is gonna be quite the clusterfuck!
What I’m taking away from this is that Linus was right from the get go : SHA1 isn’t there for security, it’s a really good algorithm for a hashtable’s hash where we really want to avoid collisions. That’s it.
If you’re thinking it’s safe because it used to be involved in security, you’re a muppet.