logoalt Hacker News

layer8 • yesterday at 8:00 PM • 3 replies • view on HN

It was a mistake to assume a fixed algorithm in the repository format and client-server protocol. I remember being surprised when I learned about that choice, being familiar with cryptographic protocols and formats where the hash algorithm is usually a parameter that can vary for each concrete hash.


Replies

loeg • today at 12:00 AM

> being familiar with cryptographic protocols and formats where the hash algorithm is usually a parameter that can vary for each concrete hash.

This flexibility ("agility") in cryptographic protocols is often seen as a mistake today, actually.

➕ show 2 replies
throw0101c • yesterday at 8:40 PM

> It was a mistake to assume a fixed algorithm in the repository format and client-server protocol.

See also perhaps Wireguard, which touts itself as not having "cryptographic agility" because they wanted to avoid all (perceived) problems and complications of IPsec. But now that PQC is (allegedly) approaching there's no easy to update things because (AIUI) there's no negotiation possible in the protocol; you're basically standing up a 'Wireguard 2.0' that runs separately than the original.

➕ show 3 replies
throwawayffffas • today at 2:14 AM

1. As others have noted, flexibility in cryptographic protocols is generally a mistake.

2. The hash function is not used for cryptographic purposes!