git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Remove non-SHA1dc sha1 implementations

From
Jeff King <peff@peff.net>
Date
Feb 24, 2020, 04:47 UTC
Message-ID
<20200224044732.GK1018190@coredump.intra.peff.net>
In-Reply-To
<20200223223758.120941-1-mh@glandium.org>
On Mon, Feb 24, 2020 at 07:37:58AM +0900, Mike Hommey wrote:
> It is 2020, and with the weakening of SHA1 security-wise, there doesn't
> seem to be a reason to support anything else than SHA1dc, with collision
> detection.

One possible reason is that they're way faster than sha1dc (block-sha1 maybe only a little, but openssl's sha1 is over twice as fast).

To be clear, I think the slowdown is worth the extra safety, but:
 - do we still want to care about people who prefer to make the tradeoff
   differently?
 - when we first switched the default to sha1dc, the idea was raised of
   continuing to use a faster implementation for non-security checksums
   (e.g., the checksums at the end of packfiles, index files, etc). I
   don't think anybody ever implemented that, but it's not a terrible
   idea. OTOH, if nobody noticed the bottleneck enough to care, maybe
   it's not worth worrying about.

I'm not convinced the answer to those questions is "yes", but I think it's worth at least raising them (and arguing against them in the commit message).

One thing that compels me is the recent report that we still build with common crypto by default on macOS, which was definitely _not_ intended. That's a bug that can be fixed, but it wouldn't have happened in the first place if we only supported sha1dc.

-Peff
Previous: Mike HommeyNext: Jeff King
Message 6 of 17 in “SHA1dc on mac”
  1. Mike HommeyFeb 12, 2020
  2. Eric SunshineFeb 12, 2020
  3. Mike HommeyFeb 12, 2020
  4. Junio C HamanoFeb 12, 2020
  5. Remove non-SHA1dc sha1 implementationsMike Hommey, Feb 23, 2020
  6. Jeff KingFeb 24, 2020
  7. Jeff KingFeb 24, 2020
  8. ppc: remove custom SHA-1 implementationÆvar Arnfjörð Bjarmason, Mar 19, 2022
  9. Junio C HamanoMar 21, 2022
  10. ppc: remove custom SHA-1 implementationÆvar Arnfjörð Bjarmason, Mar 21, 2022
  11. brian m. carlsonMar 21, 2022
  12. 0/2 Makefile + hash.h: remove PPC_SHA1 implementationÆvar Arnfjörð Bjarmason, Aug 31, 2022
  13. 2/2 Makefile: use $(OBJECTS) instead of $(C_OBJ)Ævar Arnfjörð Bjarmason, Aug 31, 2022
  14. Junio C HamanoAug 31, 2022
  15. Ævar Arnfjörð BjarmasonSep 1, 2022
  16. Junio C HamanoSep 1, 2022
  17. 1/2 Makefile + hash.h: remove PPC_SHA1 implementationÆvar Arnfjörð Bjarmason, Aug 31, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.