Compliance nonsense
Compliance nonsense
Posted Jun 24, 2022 2:31 UTC (Fri) by roguelazer (subscriber, #101286)Parent article: Whatever happened to SHA-256 support in Git?
Posted Jun 24, 2022 7:51 UTC (Fri)
by epa (subscriber, #39769)
[Link] (3 responses)
Posted Jun 26, 2022 14:49 UTC (Sun)
by jthill (subscriber, #56558)
[Link] (2 responses)
Except that exists already, it's just Git. `git init --object-format=sha256` and your repo uses sha256 only and can't talk to sha1 repos. I'd be curious how easily the web frontends' private-server options can be made to use the new object format if they don't have to talk to any poor left-behind sha1 repos either.
As a side note, afaik all known or suspected collision-generating methods require some place to hide gobs of carefully-chosen noise bits in both colliding texts. pdf is a binary format and can hide arbitrary noise. source code can not. There is no possibility that anyone get an engineered source file past even the most cursory code review. The garbage would appear the first time anyone so much as glanced at the diffs.
Posted Jun 28, 2022 11:49 UTC (Tue)
by cortana (subscriber, #24596)
[Link] (1 responses)
Posted Jul 15, 2022 15:31 UTC (Fri)
by epa (subscriber, #39769)
[Link]
Compliance nonsense
Compliance nonsense
Compliance nonsense
Compliance nonsense
