Git 3.0's upcoming SHA-256 default will be a costly mistake

18 points by mort


pyfisch

The article is wrong unless I am mistaken or the git documentation is outdated. Local repositories with SHA-256 hashes will be able to push and pull from remote repositories that use SHA-1 (and vice-versa) Both hashes for each object are stored on disk and translated in the fly. This sidesteps the incompatible version issue mostly.

https://git-scm.com/docs/hash-function-transition

mort

I don't know that ai agree with the author, that it's a mistake but I found the topic extremely interesting. I use a lot of software which pretty much assumes that a SHA1 is a permanent identifier of a commit; Yocto recipes, Nix, git submodules, tools like repo and gclient, etc. If repositories start rewriting their history to migrate to SHA256 and the old commits get garbage collected, this will result in massive breakage across all sorts of things and it'll be my job to find workarounds for a lot of it.

So I'm interested in seeing a lobste.rs discussion on the topic.

(Oh and it's finally an opportunity to use the merkle-trees tag! Git and other DVCSes are the only interesting applications of merkle trees as far as I'm concerned)

hailey

There’s one glaring hole in Scott’s “trust is in the distribution” argument specifically as it relates to GitHub which is that GitHub commingles objects across the whole fork network. Only the refs namespace is separated.

You don’t need to breach GitHub’s authentication to get a forged object into rust-lang/rust. It is much simpler - you fork the repo and push the forged object to your fork. It is then visible in the parent.

I am actually quite surprised that the article overlooks this angle given that Scott was a cofounder of GitHub.

df

I had this same experience working on a proprietary backup system that used hashes heavily in 2016 or so. “FIPS says we can only use SHA-256.” “But we use hashes for deduplication, not security.” “Doesn’t matter, FIPS says it.” “But we have thousands of users. Many are on older CPUs where that hash is expensive.” “Doesn’t matter.” “Can we just throw truncated SHA-256 in the same field as SHA-1 and call it a day?” “No.” Anyway we upgraded all our users to SHA-256.