git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: About git and the use of SHA-1

From
Andreas Ericsson <ae@op5.se>
Date
Apr 29, 2008, 07:21 UTC
Message-ID
<4816CC80.9080705@op5.se>
In-Reply-To
<f9d2a5e10804290009p17d291d5wf14e2bb58bedca63@mail.gmail.com>
Russ Dill wrote:
Show 13 quoted lines
>>  Colliding objects can never enter a repository. Git is lazy and will reuse the
>>  already existing colliding object with the same name instead.
>>
> 
> I think you are missing the point. One of the pluses behind originally
> using SHA-1 and the signed tags is that the system as a whole is
> cryptographically secure. You can verify from the public key of
> whoever made the tag that yes, this really is the source and history
> they tagged. Not only can DNS attacks be made, fooling users into
> thinking that they are really connecting to kernel.org, or whatever
> else server they expect to be connecting to, but also, the server
> itself may be hacked and objects replaced.
> 

If the server is hacked and objects are replaced, they will either no longer match their cryptographic signature, meaning they'll be new objects or git will determine that they are corrupt, or they *will* match an existing object, but then that object won't be propagated to other repositories since git refuses to overwrite already existing objects. Either way, gits refusal to overwrite objects it already has plays a part in making malicious actions futile, since malicious code is only worth something if it's propagated and actually used.

> I'm just not sure how much time it would take to find a collision.
Even crypto-experts are arguing about that, so I'm not surprised.
-- 
Andreas Ericsson                   andreas.ericsson@op5.se
OP5 AB                             www.op5.se
Tel: +46 8-230225                  Fax: +46 8-230231
Previous: Russ DillNext: Sverre Rabbelier
Message 7 of 38 in “About git and the use of SHA-1”
  1. Henrik AustadApr 28, 2008
  2. Daniel BarkalowApr 28, 2008
  3. Henrik AustadApr 28, 2008
  4. Daniel BarkalowApr 28, 2008
  5. Andreas EricssonApr 29, 2008
  6. Russ DillApr 29, 2008
  7. Andreas EricssonApr 29, 2008
  8. Sverre RabbelierApr 29, 2008
  9. Andreas EricssonApr 29, 2008
  10. Paolo BonziniApr 29, 2008
  11. Andreas EricssonApr 29, 2008
  12. Paolo BonziniApr 29, 2008
  13. Russ DillApr 29, 2008
  14. Jurko GospodnetićApr 29, 2008
  15. Russ DillApr 29, 2008
  16. Geoffrey IrvingApr 29, 2008
  17. Daniel BarkalowApr 29, 2008
  18. Dmitry PotapovApr 29, 2008
  19. Andreas EricssonApr 29, 2008
  20. Nicolas PitreApr 29, 2008
  21. Geoffrey IrvingApr 29, 2008
  22. Nicolas PitreApr 29, 2008
  23. Geoffrey IrvingApr 29, 2008
  24. Nicolas PitreApr 29, 2008
  25. Geoffrey IrvingApr 29, 2008
  26. Daniel BarkalowApr 29, 2008
  27. Geoffrey IrvingApr 29, 2008
  28. Fredrik SkolmliApr 29, 2008
  29. Geoffrey IrvingApr 29, 2008
  30. Fredrik SkolmliApr 29, 2008
  31. Martin LanghoffApr 30, 2008
  32. Geoffrey IrvingApr 30, 2008
  33. David BrownApr 30, 2008
  34. Martin LanghoffApr 30, 2008
  35. Matthieu MoyApr 29, 2008
  36. Fredrik SkolmliApr 29, 2008
  37. Tom WidmerApr 29, 2008
  38. Tom WidmerApr 29, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.