Skip to the content.

G+: Here's a post from the Subversion developers explaining …

David Coles
Here's a post from the Subversion developers explaining a little bit more about why Subversion broke (by default SHA-1 is used for content deduplication) and ways to avoid it.

They also include a detection script which is pretty simple - just look for files whom have the same prefix of SHA-1 blocks as the SHAttered PDFs (since they only differ by two 512-bit 'near-collision' blocks).

Subversion SHA1 Collision Problem Statement - Prevention and Remediation Options - blogs.collab.net


(+1's) 1