Git 3.0 will make SHA-256 the new default content hashing algorithm and it will be an incomprehensibly expensive and ultimately valueless and avoidable global nightmare.
Good practice != Something that ensures security. As I said, it’s an even better practice to just host your own fork if what you want is security. The reason to use git hashes is mostly so you don’t have to trust the author following semver in there version number. It’s a matter of ensuring that your code will always compile, not a security feature.
Have you read the article? Your arguments derive from an assumption of “sha1 is mutable, sha256 is immutable”. First of all, every hashing algorithm is going to have collisions, that’s an unavoidable “feature” of hashes. And sha1 is in no way “mutable”, it takes a great amount of effort (and money) to generate a collision. Furthermore, those collisions are not arbitrary. You have to calculate them beforehand. As the article says: what is more likely? Paying 40k€ in compute time to generate a single collision? Or just paying an open source maintainer 40k€ to let you do 1 new commit that most people are going to download anyway?
Yes I read the article. I don’t agree with all the conclusions.
Now is the best time to change to a new algo. SHA1 is not completely broken yet. It most probably will be at some point.
Also AFAIK they will have compatibility tools for SHA1 repos in git. I don’t see the big deal with the path they chose.
We will probably nor agree on that one. I think the hashes are important and that they are mutable right new with effort and later without. It’s okay that we don’t agree though. The git maintainers have made their decision anyways.
Good practice != Something that ensures security. As I said, it’s an even better practice to just host your own fork if what you want is security. The reason to use git hashes is mostly so you don’t have to trust the author following semver in there version number. It’s a matter of ensuring that your code will always compile, not a security feature.
Have you read the article? Your arguments derive from an assumption of “sha1 is mutable, sha256 is immutable”. First of all, every hashing algorithm is going to have collisions, that’s an unavoidable “feature” of hashes. And sha1 is in no way “mutable”, it takes a great amount of effort (and money) to generate a collision. Furthermore, those collisions are not arbitrary. You have to calculate them beforehand. As the article says: what is more likely? Paying 40k€ in compute time to generate a single collision? Or just paying an open source maintainer 40k€ to let you do 1 new commit that most people are going to download anyway?
Yes I read the article. I don’t agree with all the conclusions.
Now is the best time to change to a new algo. SHA1 is not completely broken yet. It most probably will be at some point.
Also AFAIK they will have compatibility tools for SHA1 repos in git. I don’t see the big deal with the path they chose.
We will probably nor agree on that one. I think the hashes are important and that they are mutable right new with effort and later without. It’s okay that we don’t agree though. The git maintainers have made their decision anyways.