git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: About git and the use of SHA-1

From
Andreas Ericsson <ae@op5.se>
Date
Apr 29, 2008, 14:37 UTC
Message-ID
<481732C0.5020208@op5.se>
In-Reply-To
<48171D24.9000104@gnu.org>
Paolo Bonzini wrote:
Show 29 quoted lines
> 
>> I can think of one way to make git a lot more resilient to hash
>> collisions, regardless of which hash is used, namely: Add the length
>> of the hashed object to the hash.
> 
> Not really, because most attacks are about collisions, not second 
> preimages.  They produce two 64-byte blocks (hence, same length) with 
> the same hash value.
> 
> As such, they allow to change a blob that *the attacker* injected in the 
> repository.  The way the more "spectacular" attacks are devised requires 
> a "language" with conditional expressions -- for documents, for example, 
> Postscript is used.  If you prepare a postscript file whose code is
> 
>    if (AAAA == BBBB)
>      typeset document 1
>    else
>      typeset document 2
> 
> where AAAA and BBBB are collisions, and you change it to "if (BBBB == 
> BBBB) the hash will be the same, but the outcome will be document 1 
> instead of document 2.
> 
> The fact that this requires having the two "behaviors" in the blob is 
> not a big deal for source code, going in the wrong branch of an "if" can 
> be an attack.  On the other hand, it makes adding the length useless for 
> collision attacks.  True, it wouldn't be useless for second preimage 
> attacks, but SHA-1 is still secure with respect to those.
> 

So what you're saying is that if someone owns a repository and adds a file to it, he can then replace his entire repository with an identical one where the good file is replaced with a bad one, and this will affect people who clone *after* the file gets replaced.

Gee, that's one fiendishly large attack vector, quite apart from the fact that said author first has to come up with a program that gets widespread enough that a lot of people all of a sudden wants to use it, but not so widespread that anyone would want to review it before using it.

I remain unconvinced as to whether or not SHA1 is, for all practical purposes, cryptographically secure for git's uses. Sure, evil programmers can screw you over if you use their software without reviewing it, but that's hardly due to git using a particular cryptographic algorithm.

Otoh, I'm not familiar enough with the nomenclature to say with 100% certainty what's cryprographically secure and what isn't. I just know that there are no collision-less hashes, so whatever "cryptographically secure" really means wrt hashes, "100% collision-free" isn't it.

-- 
Andreas Ericsson                   andreas.ericsson@op5.se
OP5 AB                             www.op5.se
Tel: +46 8-230225                  Fax: +46 8-230231
Previous: Paolo BonziniNext: Paolo Bonzini
Message 11 of 38 in “About git and the use of SHA-1”
  1. Henrik AustadApr 28, 2008
  2. Daniel BarkalowApr 28, 2008
  3. Henrik AustadApr 28, 2008
  4. Daniel BarkalowApr 28, 2008
  5. Andreas EricssonApr 29, 2008
  6. Russ DillApr 29, 2008
  7. Andreas EricssonApr 29, 2008
  8. Sverre RabbelierApr 29, 2008
  9. Andreas EricssonApr 29, 2008
  10. Paolo BonziniApr 29, 2008
  11. Andreas EricssonApr 29, 2008
  12. Paolo BonziniApr 29, 2008
  13. Russ DillApr 29, 2008
  14. Jurko GospodnetićApr 29, 2008
  15. Russ DillApr 29, 2008
  16. Geoffrey IrvingApr 29, 2008
  17. Daniel BarkalowApr 29, 2008
  18. Dmitry PotapovApr 29, 2008
  19. Andreas EricssonApr 29, 2008
  20. Nicolas PitreApr 29, 2008
  21. Geoffrey IrvingApr 29, 2008
  22. Nicolas PitreApr 29, 2008
  23. Geoffrey IrvingApr 29, 2008
  24. Nicolas PitreApr 29, 2008
  25. Geoffrey IrvingApr 29, 2008
  26. Daniel BarkalowApr 29, 2008
  27. Geoffrey IrvingApr 29, 2008
  28. Fredrik SkolmliApr 29, 2008
  29. Geoffrey IrvingApr 29, 2008
  30. Fredrik SkolmliApr 29, 2008
  31. Martin LanghoffApr 30, 2008
  32. Geoffrey IrvingApr 30, 2008
  33. David BrownApr 30, 2008
  34. Martin LanghoffApr 30, 2008
  35. Matthieu MoyApr 29, 2008
  36. Fredrik SkolmliApr 29, 2008
  37. Tom WidmerApr 29, 2008
  38. Tom WidmerApr 29, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.