Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It doesn't break supply chain security for anybody with power to change the situation.


It is an easy to overlook this, but even for someone in position of power to change, creating different code with the same hash is borderline impossible.


Non-sequitor? They're not providing a (sha-1) hash, they're providing source code to integration partners using their business channels, not public git providers. Those business channels include contracts etc to "secure their supply chain".

You and I aren't in those business channels, and we're not being given anything with a hash. There's simply no hash to collide with?


A git hash is cryptographically secure. It doesn't matter how you distribute it. That is the entire point you're missing.


The Google Drive link is to a simple tarball, not a git artifact.


Yes, that is the problem, as the titles says "Google has stopped pushing Git tags". No git tags, no cryptographic content hash.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: