git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: NIST's policy: sha-1 until 2010, after 2010 sha-2.

From
David Symonds <dsymonds@gmail.com>
Date
Dec 29, 2007, 04:45 UTC
Message-ID
<ee77f5c20712282045ha230f42n3e68477229deb199@mail.gmail.com>
In-Reply-To
<998d0e4a0712282027y6e625141jcef90bd38fb83b75@mail.gmail.com>
On Dec 29, 2007 3:27 PM, J.C. Pizarro <jcpiza@gmail.com> wrote:
Show 6 quoted lines
> Dear Linus Torvalds,
>
> What do you think to do when your git has to change from SHA-1 to SHA-2
>   because of the weaker collision-resistance of SHA-1 in the next years?
>
>     (e.g. from an damn developer trying to commit a collisioned-SHA-1 file)

It's a non-issue. The closest-to-practical attack method on SHA-1 is a collision-finding attack, not a second pre-image attack, which means you can find two messages with the same hash. As far as I know, there's no significant weakness known for finding a pre-image, which would be the most practical way of weakening Git's "security" via SHA-1 substitution.

Regardless, the use of SHA-1 in Git isn't primarily for security, though it is a nice side-effect. The SHA-1 is there for reliability in addressing and as a good hash.

Dave.
Previous: J.C. PizarroNext: David Brown
Message 2 of 3 in “NIST's policy: sha-1 until 2010, after 2010 sha-2.”
  1. J.C. PizarroDec 29, 2007
  2. David SymondsDec 29, 2007
  3. David BrownDec 29, 2007

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.