Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Tag signatures only cover the mapping from tag name to commit hash. In other words, specifying a manually-verified commit hash is actually more secure.

Tag signatures are mostly worthless now from a crypto point of view -- with the caveat that you can still get some value from them if you still trust sha1 to be secure against second-preimage attacks.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: