logoalt Hacker News

amluto • yesterday at 11:18 PM • 1 reply • view on HN

> I could replace a commit from 2010 with a malicious one

How? Remember, there are (currently, anyway) no known SHA-1 preimage attacks.


Replies

mort96 • yesterday at 11:37 PM

We're discussing a hypothetical situation where SHA-1 gets even more broken. From my original comment in this thread (https://news.ycombinator.com/item?id=49924179#49925367):

> If I can forge commits with any SHA1 hash at will

We probably don't want to wait until there are practical pre-image attacks discovered to change away from SHA-1.

➕ show 1 reply