git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Re: Merge with git-pasky II.

From
Linus Torvalds <torvalds@osdl.org>
Date
Apr 17, 2005, 17:34 UTC
Message-ID
<Pine.LNX.4.58.0504171014430.7211@ppc970.osdl.org>
In-Reply-To
<20050417152841.GA6157@elte.hu>
On Sun, 17 Apr 2005, Ingo Molnar wrote:
> 
> in fact, this attack cannot even be proven to be malicious, purely via 
> the email from Malice: it could be incredible bad luck that caused that 
> good-looking patch to be mistakenly matching a dangerous object.
I really hate theoretical discussions. 

The fact is, a lot of _crap_ engineering gets done because of the question "what if?". It results in over-engineering, often to the point where the end result is quite a lot measurably worse than the sane results.

You are _literally_ arguing for the equivalent of "what if a meteorite hit my plane while it was in flight - maybe I should add three inches of high-tension armored steel around the plane, so that my passengers would be protected".

That's not engineering. That's five-year-olds discussing building their imaginary forts ("I want gun-turrets and a mechanical horse one mile high, and my command center is 5 miles under-ground and totally encased in 5 meters of lead").

I absolutely _hate_ doing engineering on the principle of "this might be possible in theory", and I'm violently opposed to it. So far, I have not heard a single argument that I consider even _remotely_ likely.

The thing is, even if you can force a hash collission by sending somebody a patch, it's really pretty much almost guaranteed that the patch is not just "a few strange characters", unless sha1 is really broken to the point where it's not cryptographically secure _at_all_.

In other words, unless somebody finds a way to make sha1 appear as nothing more than a complicated set of parity bits, all brute-force "get the same sha1" is likely to be about generating a really strange blob based on the thing you want to replace - and by "really strange" I mean total binary crap. And likely _much_ bigger too. And by "much bigger" I mean "possibly gigabytes of data".

And the thing is, _if_ somebody finds a way to make sha1 act as just a complex parity bit, and comes up with generating a clashing object that actually makes sense, then going to sha256 is likely pointless too - I think the algorithm is basically the same, just with more bits. If you've broken sha1 to the point where it's _that_ breakable, then you've likely broken sha256 too. Nobody has ever proven that you couldn't break sha256 with some really clever algorithm...

So if you start playing "what if?" games, dammit, I can play mine.

If we want to have any kind of confidence that the hash is reall yunbreakable, we should make it not just longer than 160 bits, we should make sure that it's two or more hashes, and that they are based on totally different principles.

And we should all digitally sign every single object too, and we should use 4096-bit PGP keys and unguessable passphrases that are at least 20 words in length. And we should then build a bunker 5 miles underground, encased in lead, so that somebody cannot flip a few bits with a ray-gun, and make us believe that the sha1's match when they don't. Oh, and we need to all wear aluminum propeller beanies to make sure that they don't use that ray-gun to make us do the modification _outselves_.

And the thing is, that's just crazy talk. The difference between a crazy person and an intelligent one is that the crazy one doesn't realize what makes sense in the world. The goal of good engineering is not to ask "what if?", but to ask "how do I make this work as well as possible".

So please stop with the theoretical sha1 attacks. It is simply NOT TRUE that you can generate an object that looks halfway sane and still gets you the sha1 you want. Even the "breakage" doesn't actually do that. And if it ever _does_ become true, it will quite possibly be thanks to some technology that breaks other hashes too.

So until proven otherwise, I worry about accidental hashes, and in 160 bits of good hashing, that just isn't an issue either. Anybody who compares a 128-bit md5-sum to a 160-bit sha1 doesn't understand the math. It didn't get "slightly less likely" to happen. It got so _unbelievably_ less likely to happen that it's not even funny.

				Linus
Previous: Ingo MolnarNext: Herbert Xu
Message 41 of 130 in “Merge with git-pasky II.”
  1. Petr BaudisApr 14, 2005
  2. Christopher LiApr 13, 2005
  3. Petr BaudisApr 14, 2005
  4. Christopher LiApr 13, 2005
  5. Linus TorvaldsApr 14, 2005
  6. Christopher LiApr 14, 2005
  7. Paul JacksonApr 14, 2005
  8. Christopher LiApr 14, 2005
  9. Paul JacksonApr 14, 2005
  10. Junio C HamanoApr 14, 2005
  11. Linus TorvaldsApr 14, 2005
  12. Junio C HamanoApr 14, 2005
  13. Linus TorvaldsApr 14, 2005
  14. Junio C HamanoApr 14, 2005
  15. Petr BaudisApr 14, 2005
  16. Junio C HamanoApr 14, 2005
  17. Linus TorvaldsApr 14, 2005
  18. Junio C HamanoApr 14, 2005
  19. Petr BaudisApr 14, 2005
  20. Linus TorvaldsApr 15, 2005
  21. Barry SilvermanApr 15, 2005
  22. David WoodhouseApr 15, 2005
  23. Linus TorvaldsApr 15, 2005
  24. David WoodhouseApr 15, 2005
  25. C. Scott AnanianApr 15, 2005
  26. Linus TorvaldsApr 15, 2005
  27. Johannes SchindelinApr 16, 2005
  28. David WoodhouseApr 17, 2005
  29. Paul JacksonApr 15, 2005
  30. Simon FowlerApr 16, 2005
  31. David LangApr 16, 2005
  32. Simon FowlerApr 16, 2005
  33. Petr BaudisApr 16, 2005
  34. Simon FowlerApr 16, 2005
  35. Linus TorvaldsApr 16, 2005
  36. David LangApr 16, 2005
  37. Ingo MolnarApr 17, 2005
  38. Brad RobertsApr 17, 2005
  39. Ingo MolnarApr 17, 2005
  40. Ingo MolnarApr 17, 2005
  41. Linus TorvaldsApr 17, 2005
  42. Herbert XuApr 17, 2005
  43. Linus TorvaldsApr 17, 2005
  44. Herbert XuApr 17, 2005
  45. Petr BaudisApr 17, 2005
  46. Kenneth JohanssonApr 17, 2005
  47. Herbert XuApr 18, 2005
  48. Petr BaudisApr 18, 2005
  49. Linus TorvaldsApr 17, 2005
  50. Sanjoy MahajanApr 18, 2005
  51. Ingo MolnarApr 18, 2005
  52. Sanjoy MahajanApr 16, 2005
  53. Linus TorvaldsApr 16, 2005
  54. ls-tree enhancementsJunio C Hamano, Apr 15, 2005
  55. Petr BaudisApr 15, 2005
  56. Junio C HamanoApr 15, 2005
  57. David WoodhouseApr 15, 2005
  58. Ingo MolnarApr 15, 2005
  59. David WoodhouseApr 15, 2005
  60. Ingo MolnarApr 15, 2005
  61. David WoodhouseApr 15, 2005
  62. Johannes SchindelinApr 15, 2005
  63. Theodore Ts'oApr 15, 2005
  64. Linus TorvaldsApr 15, 2005
  65. David WoodhouseApr 15, 2005
  66. Linus TorvaldsApr 15, 2005
  67. Paul JacksonApr 15, 2005
  68. C. Scott AnanianApr 15, 2005
  69. Paul JacksonApr 15, 2005
  70. Christopher LiApr 14, 2005
  71. Petr BaudisApr 14, 2005
  72. Live Merging from remote repositoriesBarry Silverman, Apr 14, 2005
  73. Junio C HamanoApr 14, 2005
  74. Question about git process modelBarry Silverman, Apr 15, 2005
  75. Erik van KonijnenburgApr 14, 2005
  76. Petr BaudisApr 14, 2005
  77. Junio C HamanoApr 14, 2005
  78. Christopher LiApr 14, 2005
  79. Petr BaudisApr 14, 2005
  80. Christopher LiApr 14, 2005
  81. Christopher LiApr 14, 2005
  82. Christopher LiApr 14, 2005
  83. Junio C HamanoApr 15, 2005
  84. Christopher LiApr 14, 2005
  85. Junio C HamanoApr 15, 2005
  86. Christopher LiApr 15, 2005
  87. Junio C HamanoApr 15, 2005
  88. Petr BaudisApr 15, 2005
  89. Junio C HamanoApr 15, 2005
  90. Petr BaudisApr 15, 2005
  91. Junio C HamanoApr 15, 2005
  92. Junio C HamanoApr 15, 2005
  93. Linus TorvaldsApr 15, 2005
  94. Petr BaudisApr 14, 2005
  95. git mergePetr Baudis, Apr 14, 2005
  96. Linus TorvaldsApr 15, 2005
  97. Petr BaudisApr 15, 2005
  98. Linus TorvaldsApr 15, 2005
  99. Petr BaudisApr 15, 2005
  100. Linus TorvaldsApr 16, 2005
  101. Daniel BarkalowApr 16, 2005
  102. Linus TorvaldsApr 16, 2005
  103. Daniel BarkalowApr 16, 2005
  104. Linus TorvaldsApr 16, 2005
  105. Daniel BarkalowApr 16, 2005
  106. Paul JacksonApr 16, 2005
  107. Petr BaudisApr 16, 2005
  108. Junio C HamanoApr 15, 2005
  109. C. Scott AnanianApr 15, 2005
  110. Petr BaudisApr 15, 2005
  111. Junio C HamanoApr 15, 2005
  112. 1/2 merge-trees script for Linus gitJunio C Hamano, Apr 15, 2005
  113. 2/2 merge-trees script for Linus gitJunio C Hamano, Apr 15, 2005
  114. 3/2 merge-trees script for Linus gitJunio C Hamano, Apr 15, 2005
  115. Linus TorvaldsApr 16, 2005
  116. Junio C HamanoApr 16, 2005
  117. Linus TorvaldsApr 16, 2005
  118. Linus TorvaldsApr 16, 2005
  119. Junio C HamanoApr 16, 2005
  120. Byteorder fix for read-tree, new -m semantics version.Junio C Hamano, Apr 16, 2005
  121. 1/2 Add --stage to show-files for new stage dircache.Junio C Hamano, Apr 16, 2005
  122. 2/2 Add --stage to show-files for new stage dircache.Junio C Hamano, Apr 16, 2005
  123. Issues with higher-order stages in dircacheJunio C Hamano, Apr 16, 2005
  124. Junio C HamanoApr 17, 2005
  125. Linus TorvaldsApr 17, 2005
  126. Junio C HamanoApr 17, 2005
  127. Summary of "read-tree -m O A B" mechanismJunio C Hamano, Apr 17, 2005
  128. Linus TorvaldsApr 16, 2005
  129. Linus TorvaldsApr 16, 2005
  130. Junio C HamanoApr 16, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.