Re: About git and the use of SHA-1
- From
- Jurko Gospodnetić <jurko.gospodnetic@docte.hr>
- Date
- Apr 29, 2008, 12:46 UTC
- Message-ID
- <481718AF.8090000@docte.hr>
- In-Reply-To
- <f9d2a5e10804290009p17d291d5wf14e2bb58bedca63@mail.gmail.com>
Show 5 quoted lines
> I think you are missing the point. One of the pluses behind originally > using SHA-1 and the signed tags is that the system as a whole is > cryptographically secure. You can verify from the public key of > whoever made the tag that yes, this really is the source and history > they tagged.
I am not really sure I follow this.... how can you 'verify from the public key of whoever made the tag' that the SHA-1 hash is correct!? SHA-1 does not have anything do with any externally provided keys or have I managed to get something confused here?
Best regards,
Jurko Gospodnetić