1. 39
  1.  

  2. 3

    Using 160 bits from another hash function is silly, but his point that the size of the commit is hashed as well does help and it does sound like it would mitigate this collision attack.

    The PDF attack demonstrated wasn’t a preimage attack was it? If it wasn’t, we have a lot less to be concerned about. Making two arbitrary pieces of data collide in a hash function is one thing, but finding another piece of data which hashes to a particular hash is different and more difficult.

    1. [Comment removed by author]

      1. 2

        You do sound like a dick because I wasn’t defending SHA1 and you are making assumptions about people and their expertise levels.

        You should relax, this isn’t HN, we have conversations here without attacking eachother.

      2. 5

        Using 160 bits from another hash function is silly

        Note also his own followup.