Victor Kropp

Git 3.0 to use SHA-256 hashes

Git is used everywhere in software development. And this very blog is also stored in Git. Obviously, I use Git a lot. I even have a regularly updated blog post with various tips and tricks.

Git uses SHA-1 hashes to address contents it stores. The most important word in this sentence is address. Cause the aformentioned hash is not intended to provide security or verification.

The upcoming Git 3.0 is going to switch the default for commit hashes from SHA-1 to SHA-256, the newer more secure algorithm. It is being done to improve the security, however there is no real attack vector to abuse the weakness of the SHA-1 algorithm. And there are other ways to improve the security, for example, by introducing additional content hashes, not used for addressing.

The planned switch would create a dilemma for the whole community. The repository can have only one addressing, either with SHA-1 or SHA-256.

If we believe that SHA-256 is better (whatever it means) we must convert our repositories to the newer standard and rehash all objects (files, commits, etc.) But this operation by itself can be insecure and there are no tools to validate the conversion. This also would render all existing links, for example to GitHub, obsolete and make the repository incompatible with older versions of tools.

And if we won’t convert the existing repositories, it could seem as though they are no longer secure.

Git 3.0 may repeat the mistakes of Python 3.

git100DaysToOffload #100DaysToOffload/#18

Subscribe to all blog posts via RSS