news.volyx.in

Git 3.0's upcoming SHA-256 default will be a costly mistake (blog.gitbutler.com)

579 points by chmaynard · 9 days ago · 536 comments on HN

Article summary

The upcoming Git 3.0 release will change the default hashing algorithm from SHA-1 to SHA-256, which the author believes will be a costly and unnecessary change. The author argues that SHA-1 is still secure enough for Git's purposes and that the benefits of SHA-256 are not significant enough to justify the costs of migration. The change will require repositories to be rehashed, which will break external references to commits. The author predicts that this will cause frustration and problems for users, especially those with existing external references to commits.

Main themes

  • Git 3.0 migration
  • SHA-1 vs SHA-256
  • repository rehashing
  • external reference breaking
  • security risks
  • supply chain attacks
  • migration costs and benefits
  • repository integrity

What commenters say

  • The migration to SHA-256 is unnecessary and will cause significant problems for users.
  • The benefits of SHA-256 over SHA-1 are not significant enough to justify the costs of migration.
  • The change will break external references to commits and cause problems for users who rely on them.
  • Rewriting Git history is a security risk and could be an opportunity for a supply chain attack.
  • The migration is not a big deal and can be easily handled by rehashing the entire repository.
  • The change is necessary for security reasons and will provide significant benefits in the long run.
  • The problem of broken external references can be solved by adding metadata to commits or using immutable tags.
  • The cost of migration will be high, but it is a necessary step to ensure the security and integrity of Git repositories.