In a well-fleshed-out post, Scott Chacon shows how unneecessary Git 3.0’s move to replace SHA-1 with SHA-256 is.

  • Kajika@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    edit-2
    5 days ago

    It’s sad to see this community only listening to people because they’re rich: there are a lot of better engineers who knows more than this guy but they’re not “co-creator of GitHub”. I read this title as boot licking silicon valley.

    That being said you don’t hash git commits for security reason : YOU SIGN YOUR COMMITS FOR SECURITY. Sorry for the caps but let’s make this visible.

    • Life is Tetris@leminal.spaceOP
      link
      fedilink
      arrow-up
      2
      ·
      3 days ago

      If you know of write-ups by others on this, you are welcome to share. It was a pretty long post, so I mentioned who authored it. If it was on, say, LWN, I wouldn’t have prefixed anything to the topic. It looks like it also helps people to avoid rich-man blogs (if they want to)!

    • Miaou@jlai.lu
      link
      fedilink
      arrow-up
      1
      ·
      4 days ago

      But signing keys can be stolen, have to be updated, revoked etc. A secure hash is an elegant way to say “this repo contains what I want”