logoalt Hacker News

lxgr • today at 8:35 AM • 0 replies • view on HN

> And so if you don't trust the server that is hosted on or the security of the transport mechanism like TLS/SSL, such that the content may be manipulated by adversaries, you think that git hashes are good enough?

Yes, they ought to be good enough. That has always been git's security model.

Note that the commit doesn't have to be communicated over the same channel as the git data.

> Well, what about someone who is fetching the commit from that server for the first time and has nothing to compare the hash against?

Then they're vulnerable. But what about somebody learning about the trusted hash in another way, e.g. a build server getting an internal call authenticated by an authorized developer?

Just because you can think of an insecure way to use git hashes doesn't mean there aren't any other, secure ones.