logoalt Hacker News

computerfriend • today at 5:12 AM • 0 replies • view on HN

The hashing algorithm's security properties are a security property of Git. This is because:

* we pin to commit hashes and expect this to refer to immutable content,

* commit and tag signatures are over the hash.

The Linux quote about trusting the distribution doesn't make sense to me, as Git is content-addressable and decentralised, although possibly at the time it was a reasonable position to take for kernel development, but [1] could equivalently happen for Git and the hash algorithm being non-broken is required for it to be noticed. Not having to trust the forge is a very desirable property.

[1]: https://lwn.net/Articles/57135/