logoalt Hacker News

singpolyma3 • today at 2:35 AM • 1 reply • view on HN

signatures are basically always computed over hashes. The only problem here is that the hashes are not secure. And this is being fixed.


Replies

kazinator • today at 2:58 AM

No, but, the hashes are features of the content tracking system that hook it together. There is no reason that a signing scheme must rely on and trust those hashes!

We can round up the bits that make up a commit in a SHA-1-based repo, and sign those bits securely; this is a thing that is possible.

➕ show 3 replies