gnu-arch-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Gnu-arch-users] Re: MD5 is broken


From: Ivan Boldyrev
Subject: [Gnu-arch-users] Re: MD5 is broken
Date: Tue, 22 Mar 2005 13:01:58 +0600
User-agent: Gnus/5.110003 (No Gnus v0.3) Emacs/21.4 (gnu/linux)

On 9055 day of my life James Blackwell wrote:
>> Why not put both detached signatures into the checksum file?
>
> What's the point of this anyways?

Flexebility.

> Unless you're unlike most uses, you're using the default hashing,
> which is [drumroll please.....] SHA-1.

But those who care, can choose.  Current Arch has no choice at all.

> Throwing asside repudation, it still takes is 8 bytes to collide an
> md5sum, and about 8 and a half bytes to collide a sha1sum...

It take 8 hours to collide an md5sum.  Colliding sha1sum takes more
time yet.

-- 
Ivan Boldyrev

              "Assembly of Japanese bicycle require great peace of mind."

Attachment: pgpkPfkSW0XGA.pgp
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]