Finally a SHA-1 collision. TL;DR: same-prefix collision, don't panic *yet*, but Git better start thinking of SHA-256 and don't trust PDFs.
Today's collision attack requires that both files be A+X0+B and A+X1+B and you don't control X0 or X1.
-
-
And if CRC(A+X0) != CRC(A+X1) then I believe there is no B for which CRC(A+X0+B) == CRC(A+X1+B).
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.