Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

1. git uses SHA-1, not MD5; former has problems, but is still better than latter

2. git stores the length of a blob before hashing [1] which makes it harder (but not impossible) to perform such attacks [2]

[1] http://www.git-scm.com/book/en/v2/Git-Internals-Git-Objects#... [2] http://blogs.msdn.com/b/oldnewthing/archive/2004/05/19/13493...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: