git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Migrating away from SHA-1?

From
EWEric Wong <e@80x24.org>
Date
Jun 18, 2016, 03:30 UTC
Message-ID
<20160618033019.GB11307@dcvr.yhbt.net>
In-Reply-To
<02b42587-3643-1c2e-c249-313ec96bcdca@gaspard.io>
Leo Gaspard <leo@gaspard.io> wrote:
> First, sorry for not having this message threaded: I'm not subscribed to
> the list and haven't found a way to get a Message-Id from gmane.

Appending "/raw" to the gmane URL will get you the raw message with full headers:

  article.gmane.org/gmane.comp.version-control.git/$NUMBER/raw
you can also use that article $NUMBER via NNTP on news.gmane.org
> So, my questions to the git team:

It is customary to Cc: all relevant parties involved with that thread since they may not all be subscribed, either.

Show 9 quoted lines
>  * Is there a consensus, that git should migrate away from SHA-1 before
> it gets a collision attack, because it would mean chosen-prefix
> collision isn't far away and people wouldn't have the time to upgrade?
>  * Is there a consensus, that Peter Anvin's amended transition plan is
> the way to go?
>  * If the two conditions above are fulfilled, has work started on it
> yet? (I guess as Brian Carlson had started his work 9 weeks ago and he
> was speaking about working on it on the week-end he should have finished
> it now, so excluding this)

AFAIK, brian is still working on it. Last series on the matter begins here: http://mid.gmane.org/20160607005716.69222-2-sandals@crustytoothpaste.net I'm just on the sidelines observing :)

>  * If the two first conditions are fulfilled, is there anything I could
> do to help this transition? (including helping Brian if his work hasn't
> actually ended yet)
Previous: Leo GaspardNext: brian m. carlson
Message 2 of 3 in “Re: Migrating away from SHA-1?”
  1. Leo GaspardJun 18, 2016
  2. Eric WongJun 18, 2016
  3. brian m. carlsonJun 24, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.