git/list[1] front-page[2] threads[3] people[4] search[5] about
 

RE: Gitorious should use CRC128 / 256 / 512 instead of SHA-1

From
rsbecker@nexbridge.com <rsbecker@nexbridge.com>
Date
Jan 16, 2023, 12:34 UTC
Message-ID
<017901d929a6$ec180f50$c4482df0$@nexbridge.com>
In-Reply-To
<3b0af57c-a144-b0e4-d353-6028b3939291@selasky.org>
On January 16, 2023 2:24 AM, Hans Petter Selasky wrote:
Show 9 quoted lines
>On 1/15/23 00:59, brian m. carlson wrote:
>> However, Git is moving in the direction of stronger cryptographic
>> algorithms, rather than insecure hashing algorithms.  I don't think
>> your proposal is a good idea, nor do I think it's likely to be adopted.
>
>I disagree. There is no need for signing in a version control system. It just makes it
>harder to change things, like the right-to-repair. In my eyes there is a high chance
>of abuse, by vendors that do no want others to flash or edit their device
>firmwares.
The two matters are completely isolated and distinct. In the OpenSource community, anyone typically has the right to modify. Please refer to the GPLv3, ECLIPSE, and MIT licenses for example. Those are the governing documents that permit modification and define intellectual property rights. Please consult those licenses with regards to right-to-repair statements that have no legal bearing on git or any other GPL-governed software product. In my view, the issue raised is a red herring that keeps getting brought up, which does not contribute positively to this request's discussion, but would presumably would increase the hit rate on web searches, to which this reply unfortunately contributes.
The assertion of no need for signing can apply to a centralized version control system, like SVN, because users are authenticated centrally, and the contribution can be made definitive without a separate signature, providing no one with root authority on the server hacks the repository. In the architecture of a distributed version control system (specifically git for this discussion), there is no evidence of origin of changes because the commit identity is cooperative rather than being enforced by a central authority and hacking the repository by root is detectible. The assertion of signing as abuse of rights is also an opinion that, so far, has no supporting evidence given. Perhaps a paper in a refereed journal might give this position some credibility.
My point is that signing is critical in a DVCS and a major function point used by DevOps architects for adopting git in new organizations. In the regulated world, FinTech, FDA, Aviation, etc., signing contributes to the evidence of origin of changes required by PCI and SWIFT (ref: section 6 in each regulation). Without signed tags (which the establishes the change origins for releases for production use), deployment becomes less certain and less acceptable to the audit community with whom I interact on a regular basis.
--Randall
Previous: Hans Petter SelaskyNext: Hans Petter Selasky
Message 7 of 16 in “Gitorious should use CRC128 / 256 / 512 instead of SHA-1”
  1. Hans Petter SelaskyJan 13, 2023
  2. brian m. carlsonJan 14, 2023
  3. Junio C HamanoJan 15, 2023
  4. demerphqJan 15, 2023
  5. Hans Petter SelaskyJan 16, 2023
  6. Hans Petter SelaskyJan 16, 2023
  7. rsbecker@nexbridge.comJan 16, 2023
  8. Hans Petter SelaskyJan 16, 2023
  9. Junio C HamanoJan 16, 2023
  10. Michal SuchánekJan 15, 2023
  11. Hans Petter SelaskyJan 16, 2023
  12. Michal SuchánekJan 16, 2023
  13. Hans Petter SelaskyJan 16, 2023
  14. rsbecker@nexbridge.comJan 16, 2023
  15. Hans Petter SelaskyJan 16, 2023
  16. Michal SuchánekJan 16, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.