logoalt Hacker News

kazinator • today at 12:18 PM • 1 reply • view on HN

Two hashes are already used now: GPG isn't using a SHA-1 digest, but it's signing something that is using SHA-1 digests to refer to other objects.

(Inside GPG, there are configurable choices. It's possible to be using SHA-512, so in a SHA-256 git repo, you can still be using two hashes.)


Replies

lxgr • today at 12:59 PM

You are again talking about a fictional alternate reality in which git commit signatures do something like GPG_Sign(GPG_Signature_Hash(git commit || all objects referenced by commit))), instead of ours where it's GPG_Sign(GPG_Signature_Hash(git commit))), and the git commit is in turn some metadata and a git hash of a bunch of objects.

In our reality, the git hash is load bearing. You can disagree with that design choice, but you can't pretend to live in that alternate reality and design your solutions for this reality according to that.