Re: About git and the use of SHA-1
- From
Russ Dill <russ.dill@gmail.com>
- Date
- Apr 29, 2008, 16:21 UTC
- Message-ID
- <f9d2a5e10804290921y5c961fc5g88d718c40a5ff037@mail.gmail.com>
- In-Reply-To
- <481718AF.8090000@docte.hr>
On Tue, Apr 29, 2008 at 5:46 AM, Jurko Gospodnetić <jurko.gospodnetic@docte.hr> wrote:
Show 13 quoted lines
> > > I think you are missing the point. One of the pluses behind originally > > using SHA-1 and the signed tags is that the system as a whole is > > cryptographically secure. You can verify from the public key of > > whoever made the tag that yes, this really is the source and history > > they tagged. > > > > I am not really sure I follow this.... how can you 'verify from the public > key of whoever made the tag' that the SHA-1 hash is correct!? SHA-1 does not > have anything do with any externally provided keys or have I managed to get > something confused here? >
Sorry for the confusion, its about using the signed tag and the SHA-1 of the parent commits, along with their associated trees and blobs to verify the source and history. If you can't trust the signed tag, or all of the SHA-1's, you can't trust the source and history.
However, as many said, I don't think there is any reason to not trust SHA-1 is the context of source control.