Git 3.0's upcoming SHA-256 default will be a costly mistake

Git 3.0 will switch its default object hash from SHA‑1 to SHA‑256, a change that the author argues will add significant performance cost with little benefit. The article cites the upcoming release and strong Hacker News attention.

The author warns that Git 3.0’s planned shift from SHA‑1 to SHA‑256 as the default object hash will impose a huge performance penalty while offering little real advantage. He explains that Git stores data as content‑addressed objects, using SHA‑1 for twenty years because it is fast and has never produced an accidental collision in practice, despite the theoretical birthday bound of about 1.4 septillion files. Although published collision attacks have shown SHA‑1 to be “semi‑broken,” meaning deliberate collisions can be manufactured with enough compute power, the author argues these attacks are not a practical threat and that SHA‑256 does not meaningfully improve security for typical Git use. Consequently, he characterises the change as an unnecessary, costly global problem.