I tried to implement my own git from scratch. And when I got to choose a hashing algorithm, I reached the exact same conclusion as the author pretty fast.
The hashing algorithm doesn’t really matter as long as it’s good enough to prevent accidental collisions. And if there is a collision, it is extremely easy to check.
If you are about to create a new object and an object with that hash already exists, you compare the 2 objects. If they are the same, nothing happened. If they are different, you just found a collision. Throw some obscure error that will only be witnessed once in the lifetime of the universe and be done with it. Tell the user to change a single bit of the input and be done with it.
The purpose of object hashes in git was never to provide security. Security is achieved through other means.
There are some very good points in there, I would like to hear the counter-arguments.
thats bad, i got couple of repos on sha-256, i wonder what happens if they drop it, which i think they wont, do i have to like re-create them?
I don’t think they’ll drop sha256. The breaking change is that it’s now the default instead of sha1.




