|
|
|
|
|
by pawadu
3286 days ago
|
|
Here is my problem with this statement: SHA-1 can be used in different configurations for different applications. Some are secure, some are not. People making these blanket statement very clearly demonstrate that they don't understand security and cryptography. Do you really want to use a security tool written by such people? https://plus.google.com/+LinusTorvalds/posts/7tp2gYWQugL |
|
Also, git's use of SHA1 is completely broken, it's just that no-one (that we know of) has chosen to spend the money required to make evil git repositories (you can't just take existing collisions and use them in git, you would have to go find git-specific ones).