git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Gitorious should use CRC128 / 256 / 512 instead of SHA-1

From
Hans Petter Selasky <hps@selasky.org>
Date
Jan 13, 2023, 16:44 UTC
Message-ID
<7a51b925-cb0a-4b48-fc14-171006f73298@selasky.org>
In-Reply-To
<20230113163619.4ab5oyqyjrthxrwv@meerkat.local>
On 1/13/23 17:36, Konstantin Ryabitsev wrote:
Show 8 quoted lines
> I'm not sure what you mean here, but git is certainly not zero-trust. When you
> clone linux.git from git.kernel.org, you're very much trusting that:
> 
> - I (or members of my team) didn't mess with the repository
> - Linus (or someone who hacked his laptop) didn't mess with the repository
> 
> Git is tamper-evident, not tamper-proof, so by definition it cannot be
> zero-trust.
Hi,

By using a cryptographic hash algorithm, the goal is to avoid tampering you say, like tampering on the internet, ISP, cache node and so on. To me that's clearly a zero-trust thought. You don't trust the guy(s) that put down the infrastructure, neither those that provide that local cache for the GIT repository, only the master repository. SHA-1 gives a certain confidence, that if you checkout XXXXXXX, then you get a likely expected result with reduced possibility of tampering.

Anyone could intercept a CRC protected blob and re-compute the hash and send it on. But not a SHA-1 one.

I on the other hand trust the guys that put down the internet and are providing the cache nodes for GIT.

It's two different world views.
--HPS
Previous: Konstantin RyabitsevNext: Konstantin Ryabitsev
Message 15 of 26 in “Gitorious should use CRC128 / 256 / 512 instead of SHA-1”
  1. Hans Petter SelaskyJan 13, 2023
  2. Konstantin KhomoutovJan 13, 2023
  3. Hans Petter SelaskyJan 13, 2023
  4. rsbecker@nexbridge.comJan 13, 2023
  5. Hans Petter SelaskyJan 13, 2023
  6. Konstantin RyabitsevJan 13, 2023
  7. Hans Petter SelaskyJan 13, 2023
  8. rsbecker@nexbridge.comJan 13, 2023
  9. Hans Petter SelaskyJan 13, 2023
  10. Hans Petter SelaskyJan 13, 2023
  11. Konstantin RyabitsevJan 13, 2023
  12. Hans Petter SelaskyJan 13, 2023
  13. Hans Petter SelaskyJan 13, 2023
  14. Konstantin RyabitsevJan 13, 2023
  15. Hans Petter SelaskyJan 13, 2023
  16. Konstantin RyabitsevJan 13, 2023
  17. Hans Petter SelaskyJan 13, 2023
  18. Konstantin RyabitsevJan 13, 2023
  19. Hans Petter SelaskyJan 13, 2023
  20. Hans Petter SelaskyJan 13, 2023
  21. Konstantin RyabitsevJan 13, 2023
  22. Hans Petter SelaskyJan 13, 2023
  23. Hans Petter SelaskyJan 13, 2023
  24. Philip OakleyJan 13, 2023
  25. Konstantin RyabitsevJan 13, 2023
  26. Konstantin KhomoutovJan 13, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.