Git 3.0 will make SHA-256 the new default content hashing algorithm and it will be an incomprehensibly expensive and ultimately valueless and avoidable global nightmare.
In a well-fleshed-out post, Scott Chacon shows how unneecessary Git 3.0’s move to replace SHA-1 with SHA-256 is.
It’s sad to see this community only listening to people because they’re rich: there are a lot of better engineers who knows more than this guy but they’re not “co-creator of GitHub”. I read this title as boot licking silicon valley.
That being said you don’t hash git commits for security reason : YOU SIGN YOUR COMMITS FOR SECURITY. Sorry for the caps but let’s make this visible.
If you know of write-ups by others on this, you are welcome to share. It was a pretty long post, so I mentioned who authored it. If it was on, say, LWN, I wouldn’t have prefixed anything to the topic. It looks like it also helps people to avoid rich-man blogs (if they want to)!
It’s sad to see this community only listening to people because they’re rich: there are a lot of better engineers who knows more than this guy but they’re not “co-creator of GitHub”. I read this title as boot licking silicon valley.
That being said you don’t hash git commits for security reason : YOU SIGN YOUR COMMITS FOR SECURITY. Sorry for the caps but let’s make this visible.
If you know of write-ups by others on this, you are welcome to share. It was a pretty long post, so I mentioned who authored it. If it was on, say, LWN, I wouldn’t have prefixed anything to the topic. It looks like it also helps people to avoid rich-man blogs (if they want to)!
But signing keys can be stolen, have to be updated, revoked etc. A secure hash is an elegant way to say “this repo contains what I want”