logoalt Hacker News

nicoburns • yesterday at 5:24 PM • 4 replies • view on HN

From what I'd read, SHA256 in git is showing every sign of being another IPv6. In particular:

- It's implemented in a non-backwards-compatible way

- The benefits over the older model are a bit nebulous

- There's a large amount of tooling that needs to catch up, and little sign that there is movement there


Replies

kccqzy • today at 3:01 AM

It could also be another Python 3 situation: backwards incompatible, unclear benefits with many downsides (3.0 and 3.1 being very slow), large number of libraries that need to catch up.

sltkr • yesterday at 5:43 PM

The difference with IPv6 adoption is that the internet relies heavily on network effects: so long as some hosts only have an IPv4 address, you need an IPv4 address for full connectivity, but then if everyone has an IPv4 address anyway, there is no immediate need to migrate to IPv6.

(Yes us Hacker News users have plenty of use cases for IPv6, like self-hosting and peer-to-peer networking and so on; we are not the average user.)

This effect doesn't exist for the Git migration. Each repo can be updated independently; it doesn't affect users of other repositories, and most likely, the majority of devs will work on some SHA-1 repos and some SHA-256 repos with no issue.

If anything, I would compare it with the Python 2 to Python 3 migration, which was also painful, but succeeded eventually (despite being much less necessary in the first place).

➕ show 4 replies
gspr • yesterday at 5:29 PM

> - The benefits over the older model are a bit nebulous

This is far from the case with IPv6!

➕ show 2 replies
Onavo • yesterday at 5:31 PM

There's a massive push right now from top down to have secure software supply chains. Google SBOM and SigStore. It's not an organic need but if you have government customers you don't have many options.

➕ show 1 reply