Hacker News new | ask | show | jobs
by fl7305 812 days ago
Can you elaborate? Are you thinking of intentional SHA-1 has collisions? Would that work in practice?
1 comments

The history. Every time something like this attack happens people think they can read the complete git history in the repo.
If some commits are signed by people you trust, can the chain before that still be compromised?