Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
The Hacker News
1 month ago

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

By info@thehackernews.com (The Hacker News)

New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified." Everything a reviewer would check matches. The commit's hash does not. That matters

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.