Removing SHA-1 for signatures in Fedora
Removing SHA-1 for signatures in Fedora
Posted Mar 16, 2022 12:00 UTC (Wed) by pbonzini (subscriber, #60935)In reply to: Removing SHA-1 for signatures in Fedora by foom
Parent article: Removing SHA-1 for signatures in Fedora
If you have a non-malicious commit and would like to distribute a forged commit with different contents, you would need a second preimage attack, which is a very different thing from all current practical (or almost-practical) attacks on SHA-1. All such attacks are collision attacks, and would only be usable by maintainers that are themselves malicious.
