git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: About git and the use of SHA-1

From
Geoffrey Irving <irving@naml.us>
Date
Apr 29, 2008, 20:31 UTC
Message-ID
<7f9d599f0804291331v2f44bee1y29c1580d68a3107a@mail.gmail.com>
In-Reply-To
<alpine.LNX.1.00.0804291410340.19665@iabervon.org>
On Tue, Apr 29, 2008 at 11:41 AM, Daniel Barkalow <barkalow@iabervon.org> wrote:
Show 39 quoted lines
> On Tue, 29 Apr 2008, Geoffrey Irving wrote:
>
>  > On Tue, Apr 29, 2008 at 10:55 AM, Nicolas Pitre <nico@cam.org> wrote:
>  > > On Tue, 29 Apr 2008, Geoffrey Irving wrote:
>  > >
>  > >
>  > > > Sorry for the confusion: it would handwaving if I was saying git was insecure,
>  > >  > but I'm not.  I'm saying that if or when SHA1 becomes vulnerable to collision
>  > >  > attacks, git will be insecure.
>  > >
>  > >  Right.  And if or when that happens then we'll make Git secure again
>  > >  with a different hash.  In the mean time there is low return for the
>  > >  effort involved.
>  >
>  > Yes.  I wasn't trying to advocate switching, just making sure people
>  > know that the "collisions don't matter" argument is bogus.
>
>  It's bogus to say they completely don't matter, but I still claim that
>  they don't matter for the things people actually care about. If people can
>  generate collisions, they can commit a "weak" blob with a conditional that
>  can be switched by replacing the blob. But it's almost always true that
>  people could commit a blob with a conditional that can be switched by
>  something else under the attacker's more direct control. Using a better
>  hash function won't save you from a document like:
>
>  if (getdate() < 2009)
>   render_good_text
>  else
>   render_evil_text
>
>  even if it does help with:
>
>  if (AA == AA)
>   render_good_text
>  else
>   render_evil_text
>
>  If you're not checking your files for the former, you shouldn't worry
>  about the latter, because the former is much easier and more subtle.

I sincerely hope that pdf/postscript don't allow the internal rendering code to branch based on the current date. That would be an absurd security hole, and would indeed make you entirely correct. If you actually know that it is possible to write that in postscript, I would very much want to see an example.

In any case, in a binary document format that isn't insane (examples of these at least include black and white .png images of documents), a visual check of the content is sufficient to ensure that the next person who looks at it will see roughly the same visual content. Git should be (and currently is) a secure method of transferring sane binary documents.

Geoffrey
Previous: Daniel BarkalowNext: Fredrik Skolmli
Message 27 of 38 in “About git and the use of SHA-1”
  1. Henrik AustadApr 28, 2008
  2. Daniel BarkalowApr 28, 2008
  3. Henrik AustadApr 28, 2008
  4. Daniel BarkalowApr 28, 2008
  5. Andreas EricssonApr 29, 2008
  6. Russ DillApr 29, 2008
  7. Andreas EricssonApr 29, 2008
  8. Sverre RabbelierApr 29, 2008
  9. Andreas EricssonApr 29, 2008
  10. Paolo BonziniApr 29, 2008
  11. Andreas EricssonApr 29, 2008
  12. Paolo BonziniApr 29, 2008
  13. Russ DillApr 29, 2008
  14. Jurko GospodnetićApr 29, 2008
  15. Russ DillApr 29, 2008
  16. Geoffrey IrvingApr 29, 2008
  17. Daniel BarkalowApr 29, 2008
  18. Dmitry PotapovApr 29, 2008
  19. Andreas EricssonApr 29, 2008
  20. Nicolas PitreApr 29, 2008
  21. Geoffrey IrvingApr 29, 2008
  22. Nicolas PitreApr 29, 2008
  23. Geoffrey IrvingApr 29, 2008
  24. Nicolas PitreApr 29, 2008
  25. Geoffrey IrvingApr 29, 2008
  26. Daniel BarkalowApr 29, 2008
  27. Geoffrey IrvingApr 29, 2008
  28. Fredrik SkolmliApr 29, 2008
  29. Geoffrey IrvingApr 29, 2008
  30. Fredrik SkolmliApr 29, 2008
  31. Martin LanghoffApr 30, 2008
  32. Geoffrey IrvingApr 30, 2008
  33. David BrownApr 30, 2008
  34. Martin LanghoffApr 30, 2008
  35. Matthieu MoyApr 29, 2008
  36. Fredrik SkolmliApr 29, 2008
  37. Tom WidmerApr 29, 2008
  38. Tom WidmerApr 29, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.