git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Val Henson's critique of hash-based content storage systems

From
C. Scott Ananian <cscott@cscott.net>
Date
Apr 29, 2005, 20:17 UTC
Message-ID
<Pine.LNX.4.61.0504291608410.32145@cag.csail.mit.edu>
In-Reply-To
<200504291952.MAA27541@emf.net>
On Fri, 29 Apr 2005, Tom Lord wrote:
> I would expect someone to have on hand a small number of blobs that are
> different but have different hashes and, eventually, to drop said files
> into a blob-based infrastructure to wreak havoc.

This is just ridiculous. The number of known collisions in SHA1 is *exactly zero* at this point in time --- not guaranteed to stay that way, of course, but generating collisions is likely to remain relatively expensive for some time. The collisions are highly structured; they are not just arbitrary blobs. If, after doing your 2^69 work or so to generate a real honest-to-goodness SHA-1 collision, you think an attacker would "DROP THEM IN A REPOSITORY TO CREATE HAVOC"? You'd have to break into the repository, etc, and then you'd find that *NOTHING REFERENCED THEM* and so *ABSOLUTELY NOTHING WOULD HAPPEN*.

It's far more likely that SHA1 collisions will be used to generate forged X509 certificates, for a number of highly technical reasons.

Git's highly constrained and derided 'brittle' file formats also serve to protect against the collision attacks against SHA-1 which are beginning to look possible.

> So: a way to locally mark a given checksum as "controversial" seems
> prudent, to me (hence, support for such in my blob-db code/spec).

Arguably that's what *upgrades* to the spec might be for -- git has a solid philosophy of not creating 'features' unless it is sure that they are needed/will be used, and I think this is always the wise route in software development. Of much specification comes no code.

And, if you actually create a 'flexible' blob-db spec with 'room for 
expansion' -- congratulations, you've just made yourself more vulnerable 
to collision attacks.
  --scott
terrorist MI5 SKILLET hack AMLASH security KMPLEBE KUFIRE SCRANTON 
D5 SLBM LINCOLN KUDESK SMOTH Kojarena Moscow HTAUTOMAT WSBURNT Chechnya
                          ( http://cscott.net/ )
Previous: Tom LordNext: Tom Lord
Message 4 of 8 in “Val Henson's critique of hash-based content storage systems”
  1. Rob JellinghausApr 29, 2005
  2. Linus TorvaldsApr 29, 2005
  3. Tom LordApr 29, 2005
  4. C. Scott AnanianApr 29, 2005
  5. Tom LordApr 29, 2005
  6. C. Scott AnanianApr 29, 2005
  7. H. Peter AnvinApr 29, 2005
  8. Morten WelinderApr 29, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.