Re: more git updates..

From: Bernd Eckenfels
Date: Sat Apr 23 2005 - 20:32:11 EST


In article <20050423174227.51360d63.pj@xxxxxxx> you wrote:
> If something is likely to happen less than once in a billion years,
> then for all practical purposes, it won't happen.

Of course there are colliding files already available and easyly
generate-able. So a malicous attack is already possible.

Which is especially nasty because one can proof GIT obeject file system is
broken. However I dont think it is a problem for Linux Source Control
purpose, ever.

However using a combined hash might be a good idea, here. So you silence the
critics since they have no eploit samples handy. :) Or at least go with FIPS
180-2.

Greetings
Bernd
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/