HeadlinesBriefing HeadlinesBriefing.com

Git 3.0 SHA-256 Default: A Costly Mistake?

Hacker News •
×

Git 3.0's planned switch from SHA-1 to SHA-256 as the default hash algorithm is criticized as a costly, unnecessary change with little practical benefit. The author argues that SHA-1 has remained cryptographically sound for 20 years despite theoretical vulnerabilities, with no real-world collisions ever observed in Git's history. While SHA-1 is considered 'broken' in cryptographic terms due to demonstrated collision attacks like SHAttered (2017) and SHA-1 is a Shambles (2020), these require significant resources and are not feasible for accidental or widespread exploitation.

The shift to SHA-256, while more secure in theory, will impose substantial costs on developers, tools, and workflows globally—requiring repository migrations, breaking compatibility, and causing widespread disruption—for minimal gain in actual security. The author contends that the change addresses a near-impossible risk at enormous expense, calling it a 'global train wreck' for almost no practical value.

Source: Hacker News · Summarized by HeadlinesBriefing