git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Gitorious should use CRC128 / 256 / 512 instead of SHA-1

From
Hans Petter Selasky <hps@selasky.org>
Date
Jan 13, 2023, 15:15 UTC
Message-ID
<ba5f35d2-1c94-9216-6676-d845c73ad6c3@selasky.org>
In-Reply-To
<009701d9275a$678416b0$368c4410$@nexbridge.com>
On 1/13/23 15:21, rsbecker@nexbridge.com wrote:
> Signed content will no longer be verifiable. The whole Merkel Tree representing the commit history becomes easily corruptible by hackers
Hi,

As a long time open sourcer and hacker, I'm totally against signing software. Is the GIT project going to build the new infrastructure for John-Deers new tractor firmware adventure? It is totally against the values of open source craftmanship.

I don't think any of you crypto-enthusiasts understand how propritary companies use signed software to keep their power intact.

That's also an argument for using a non-crypto hash.
--HPS
Previous: Hans Petter SelaskyNext: Philip Oakley
Message 23 of 26 in “Gitorious should use CRC128 / 256 / 512 instead of SHA-1”
  1. Hans Petter SelaskyJan 13, 2023
  2. Konstantin KhomoutovJan 13, 2023
  3. Hans Petter SelaskyJan 13, 2023
  4. rsbecker@nexbridge.comJan 13, 2023
  5. Hans Petter SelaskyJan 13, 2023
  6. Konstantin RyabitsevJan 13, 2023
  7. Hans Petter SelaskyJan 13, 2023
  8. rsbecker@nexbridge.comJan 13, 2023
  9. Hans Petter SelaskyJan 13, 2023
  10. Hans Petter SelaskyJan 13, 2023
  11. Konstantin RyabitsevJan 13, 2023
  12. Hans Petter SelaskyJan 13, 2023
  13. Hans Petter SelaskyJan 13, 2023
  14. Konstantin RyabitsevJan 13, 2023
  15. Hans Petter SelaskyJan 13, 2023
  16. Konstantin RyabitsevJan 13, 2023
  17. Hans Petter SelaskyJan 13, 2023
  18. Konstantin RyabitsevJan 13, 2023
  19. Hans Petter SelaskyJan 13, 2023
  20. Hans Petter SelaskyJan 13, 2023
  21. Konstantin RyabitsevJan 13, 2023
  22. Hans Petter SelaskyJan 13, 2023
  23. Hans Petter SelaskyJan 13, 2023
  24. Philip OakleyJan 13, 2023
  25. Konstantin RyabitsevJan 13, 2023
  26. Konstantin KhomoutovJan 13, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.