GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit’s hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps “Verified.”

Everything a reviewer would check matches. The commit’s hash does not. That matters

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

A new Android malware from Google

A new Android malware from Google Source: Hacker News

Show HN: Sokoban AI Solver

Show HN: Sokoban AI Solver Source: Hacker News

Canada plans ‘nuclear renaissance’ with up to 10 reactors built by 2040

Canada plans ‘nuclear renaissance’ with up to 10 reactors built by 2040 Source: Hacker News