Finally a SHA-1 collision. TL;DR: same-prefix collision, don't panic *yet*, but Git better start thinking of SHA-256 and don't trust PDFs.
-
-
preimage=we're screwed (not even MD*2* is preimage-broken); chosen prefix=Flame, git totally broken; same prefix=git safe-ish for code.
-
If you're putting binary files in Git without carefully vetting their contents, time to start pestering the devs to switch to a better hash.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.