Linux Archive

Linux Archive (http://www.linux-archive.org/)
-   Debian Development (http://www.linux-archive.org/debian-development/)
-   -   Debian should move away from MD5 (and at best also from SHA1) (in secure APT and friends) (http://www.linux-archive.org/debian-development/711412-debian-should-move-away-md5-best-also-sha1-secure-apt-friends.html)

Christoph Anton Mitterer 10-10-2012 11:19 PM

Debian should move away from MD5 (and at best also from SHA1) (in secure APT and friends)
 
Hi folks.

AFAICS, secure APT and similar things (e.g. dpkg's file hash sums) still
use even MD5.


Wouldn't it make sense to start discussions about moving to the
"strongest" possible?
Or, like in the case of package files (dsc and friends) make a policy of
verifying all hashes, and fail if any single doesn't match?


I mean SHA-1 is far from being broken, but recently there was an
estimation on when one will see first collisions (the archive on the
NIST list requires registration, but Schneier has re-posted it on his
blog[0]).

So I guess one shouldn't delay that forever...


Cheers,
Chris.


[0] http://www.schneier.com/blog/archives/2012/10/when_will_we_se.html


All times are GMT. The time now is 10:56 AM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.