GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit’s hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps “Verified.”

Everything a reviewer would check matches. The commit’s hash does not. That matters

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Train SIM Created by Just One Person Is Being Called the Best Ever Made

Train SIM Created by Just One Person Is Being Called the Best Ever Made Source: Hacker News

The case against geometric algebra (2024)

The case against geometric algebra (2024) Source: Hacker News

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader