Hacker Newsnew | past | comments | ask | show | jobs | submit | OkayPhysicist's commentslogin

Either way, flamethrowers turn out to be remarkably effective.

Can someone more cyber-pilled than me explain what the actual risk with Git hashes being susceptible to collision attacks is? Obviously accidental collisions are problematic, but to my understanding the probability of that is still approximately zero.

Best I can tell, all a forced collision would do is let someone who already has control of a repo modify the history in a far from plausibly deniable way. Which in practical terms, they already could do simply by replacing the whole thing, because who's out here using git hashes as a security tool? Every pinning I've ever seen has been to tags (which can be modified at will), or hashes of the actual payload (which doesn't need to be the same as what git uses).


> who's out here using git hashes as a security tool

Among others, dependency management in Rust [1] and Python [2] sometimes uses references that work similar to https://github.com/rust-lang/rust/commit/ec999ed [3] to suggest one particular version of the project, authored by the specified maintainer.

Unfortunately, it means neither, unless you pushed it. The hash points to whatever the first person uploading it to github submitted. And the author/org name in the URL is window dressing: all the objects go in one big bucket regardless of push permission to one particular fork (because why wouldn't they - today, collisions are believed to be recognizable because the cheapest way to craft them results in clear tells).

[1]: https://doc.rust-lang.org/cargo/reference/specifying-depende...

[2]: https://pip.pypa.io/en/stable/topics/vcs-support/#git

[3]: N.B. the "This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository." warning Github has started to add to URLs like that.


I see commit hashes used all the time, like in yocto recipes for example

You are probably grossly overestimating the cost of custom-made clothing if you're hesitant about it while working in tech. Especially if you're buying Turkish. Have you seen the Lira lately? As an American, it's like a 2-3x buying power difference.

Another option is just paying for a laundry service. It's really not that expensive (think <$20 a week, in one of the highest cost of living areas in the world), and your clothes end up looking much better than the alternatives. I got into it because I fucking loathe folding clothing.

You would be very surprised at how well a good summer suit can breathe. If you tell your tailor that you need a suit that you can wear outside in the summer, they absolutely will point in the right direction with regards to material and fit.

There is no type of suit that will breathe well in Singapore. You just have to suffer and hope you can quickly get to an sir conditioned building.

Only if you're exceptionally lazy with it. Sure, everybody's got to have a black suit for winter weddings and funerals, but you've got a lot more freedom with your summer suit. Whole range of shirt colors, neckwear is a whole world of fashion choices, etc.

that's like saying everyone should just eat porridge, after all there are so many different combinations of ingredients you can put in it! why would you ever want to eat anything else!

To be clear to anyone reading this, that is a verbatim quote from the man's own FAQ. Wild.

It's worth reading the whole FAQ.

Decent professors distinguish between "using stuff we haven't taught yet" and "trivializing the assignment by using stuff that wasn't intended". If the assignment in an Algorithms course is to implement a square root function, calling "sqrt(x)" is obviously inappropriate. Structuring their solution using a do while() loop rather than while() loop is not.

This isn't the 90% case. At least half of CS students come in with at least a basic proficiency in programming. It's a big enough portion of the class that not boring them into ignoring the actual Computer Science parts while getting the other half up to speed is the defining issue of lower-division CS courses.

GP was describing the platonic ideal of why we have universities instead of just textbooks, so I'd venture a guess that you're the one with a biased perspective here. Sure, some students cheat, and the appropriate penalty is throwing them out of the program. But pursuing that end to the point that you forbid students from engaging in normal collaborative learning is nuts.

As you point out, there are plenty of students who flat-out copy each other. Filtering out those students does plenty to enrich the remaining students, you don't need to go on witch hunts to find ever-more subtle cheating.


Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: