Finally a SHA-1 collision. TL;DR: same-prefix collision, don't panic *yet*, but Git better start thinking of SHA-256 and don't trust PDFs.
Yes of course, that's why executable binaries (or things like PDF) are the easy way to use this attack.
-
-
But it's not really practical with source code because hopefully the evil branch would raise eyebrows.
-
That would be an interesting theme for the Underhanded C Code Contest. Make the branch and the garbage block look innocuous.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.