Skip to content

Comment on Colliding with the SHA prefix of Linux's initial Git commitparent

Comments

Code review in the Linux kernel still happens by email to a large degree.

Further up in contribution tree there is additional signing. Would that further complicate the insertion of a false commit? I am not convinced that signing is used all the way down to every contribution.

Linux probably has enough eyeballs on its source to make attacks like that unlikely anyway, but Git isn't just used by Linux.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.