logoalt Hacker News

nixpulvis • yesterday at 7:45 PM • 0 replies • view on HN

I'm going to completely ignore the first part of this post because I'm not interested in arguing about how severe the issues with SHA-1 are. I think it's accepted that there are flaws.

So given that, I'm more interested in the arguments for why migrating to SHA-256 is problematic.

The biggest issue I see, after skimming over it, is the submodule breakage for new projects trying to link to old projects. This seems solvable frankly, but is the only serious issue I see. Everything else will be worked out as software is updated IMO.