That's a system that would still be entirely vulnerable to collision attacks, though, right?
I'd imagine it would be nearly impossible to generate a collision that a.) does what you want, b.) is small enough to be unobtrusive, and c.) can be discovered in finite time with the computing power reasonably available to NSA/GCHQ/insert SIGINT organization of choice.
I asked because git uses SHA1, which might be a bit low on (c) at this point.
True. Generating collisions is doable, but a.) and b.) are still huge constraints that make it orders of magnitude more difficult.
True, it could've been easier to use fake credentials from the start