1 |
hasufell schrieb: |
2 |
> On 11/04/2015 09:56 AM, Andrew Savchenko wrote: |
3 |
>> No, it is not. The whole git tree is insecure and no better than |
4 |
>> rsync or CVS in terms of data security because SHA1 is vulnerable. |
5 |
>> |
6 |
> Another one who is confusing _any_ collision with _preimage attack_ ;) |
7 |
|
8 |
While Andrew's view is very pessimistic here, yours is decidedly optimistic. |
9 |
|
10 |
There is no known computationally feasible preimage attack against MD5, |
11 |
still that hash function is broken in serious ways with attacks already |
12 |
having real-world consequences. |
13 |
|
14 |
It would be quite naïve to assume that SHA1 will remain secure until a |
15 |
preimage attack is found. |
16 |
|
17 |
|
18 |
Best regards, |
19 |
Chí-Thanh Christopher Nguyễn |