logoalt Hacker News

quotemstr • yesterday at 5:33 PM • 5 replies • view on HN

Would the author feel the same if git had used MD5 instead of SHA-1?


Replies

schacon • yesterday at 5:39 PM

I do actually literally write in this that if it was MD5 it also would not be a problem.

➕ show 1 reply
happytoexplain • yesterday at 5:36 PM

They address this very theoretical. In short: Yes. Which makes sense if you don't treat the hash as a form of security against malice, especially in the case of attacks that are already impractical, which is the entire thrust of the article.

techjamie • yesterday at 6:59 PM

The hash isn't the security, the distribution is.

https://lore.kernel.org/git/Pine.LNX.4.58.0504291221250.1890...

As linked by another commenter in this thread, Linus worked out years ago that even if someone inserted a malicious object into the kernel repo, it would at best be a nuisance and not a major concern.

eviks • today at 2:36 AM

Follow the ethos of the quote master!

> We could be using MD5 and it would honestly probably be just fine.