1 |
On 15 September 2014 10:56, hasufell <hasufell@g.o> wrote: |
2 |
|
3 |
> According to Robin, it's not about rebasing, it's about signing all |
4 |
> commits so that messing with the blob (even if it has the same sha-1) |
5 |
> will cause signature verification failure. |
6 |
> |
7 |
|
8 |
Correct me if I'm wrong, but wouldn't a SHA1 attack on the tree object or |
9 |
file blobs be completely invisible to the commit SHA1? |
10 |
|
11 |
As the Signature only signs content of the commit object, not any of the |
12 |
nodes it refers to. |
13 |
|
14 |
Granted, getting a tree/file object to replicate might be interesting. |
15 |
|
16 |
-- |
17 |
Kent |
18 |
|
19 |
*KENTNL* - https://metacpan.org/author/KENTNL |