git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Gitorious should use CRC128 / 256 / 512 instead of SHA-1

From
Junio C Hamano <gitster@pobox.com>
Date
Jan 16, 2023, 15:06 UTC
Message-ID
<xmqqbkmyecym.fsf@gitster.g>
In-Reply-To
<85788356-14b1-6afb-c78c-0ab889bbbb59@selasky.org>
Hans Petter Selasky <hps@selasky.org> writes:
> From what I've read the GPLv3 goes pretty far to also provide flashing
> rights for software, but what use is that, when flashing the unsigned
> software on your Samsung phone, for example, some fuse breaks in the
> hardware, and then you can no longer use certain apps on your phone?

It smells that you are conflating the signing of source material and the sealing of tivoized hardware that use cryptographic signature to tell what binaries are allowed to run on it.

The signing implemented by the software we the Git development community build is not about the latter. The source used to build binaries for your tivoized hardware can come from a VCS that is deliberately designed to allow object name collisions, and your build would just be locked out the same unless you have the signing key that pleases the hardware. Use of Git there would not make the story any different, I am afraid.

Previous: Hans Petter SelaskyNext: Michal Suchánek
Message 9 of 16 in “Gitorious should use CRC128 / 256 / 512 instead of SHA-1”
  1. Hans Petter SelaskyJan 13, 2023
  2. brian m. carlsonJan 14, 2023
  3. Junio C HamanoJan 15, 2023
  4. demerphqJan 15, 2023
  5. Hans Petter SelaskyJan 16, 2023
  6. Hans Petter SelaskyJan 16, 2023
  7. rsbecker@nexbridge.comJan 16, 2023
  8. Hans Petter SelaskyJan 16, 2023
  9. Junio C HamanoJan 16, 2023
  10. Michal SuchánekJan 15, 2023
  11. Hans Petter SelaskyJan 16, 2023
  12. Michal SuchánekJan 16, 2023
  13. Hans Petter SelaskyJan 16, 2023
  14. rsbecker@nexbridge.comJan 16, 2023
  15. Hans Petter SelaskyJan 16, 2023
  16. Michal SuchánekJan 16, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.