logoalt Hacker News

Dylan16807 • today at 7:52 AM • 1 reply • view on HN

> There is no reason that a signing scheme must rely on and trust those hashes!

Not "must", but it would be stupid to use two sets of hashes without a compelling reason.


Replies

kazinator • today at 12:18 PM

Two hashes are already used now: GPG isn't using a SHA-1 digest, but it's signing something that is using SHA-1 digests to refer to other objects.

(Inside GPG, there are configurable choices. It's possible to be using SHA-512, so in a SHA-256 git repo, you can still be using two hashes.)

➕ show 1 reply