1 |
> On 25 Jul 2022, at 15:35, Peter Stuge <peter@×××××.se> wrote: |
2 |
> |
3 |
> Mikhail Koliada wrote: |
4 |
>> This idea has been fluctuating in my head for quite a while given |
5 |
>> that the migration had happened a while ago [0] and some other |
6 |
>> major distributions have already adopted yescrypt as their default algo |
7 |
>> by now [1]. |
8 |
> |
9 |
> Please only do that based on proven merit and nothing else. |
10 |
> |
11 |
> Fedora or anyone else for that matter making a change is a truly |
12 |
> terrible reason to take any action whatsoever, since other |
13 |
> organizations are driven by /their/ interests - with Fedora in |
14 |
> particular being driven by the business interests of Red Hat. |
15 |
> |
16 |
> I consider Gentoo a leader in many regards and it makes me really |
17 |
> sad whenever Gentoo changes based on nothing more than "others did it". |
18 |
> |
19 |
|
20 |
A fair part of the motivation for the libxcrypt migration was allowing |
21 |
use of tougher hashing algorithms like yescrypt. |
22 |
|
23 |
While your concern may be valid in some contexts, it's |
24 |
not what's happening here, as Rich notes. |
25 |
|
26 |
Maybe zlogene's email should have explicitly stated |
27 |
that yescrypt has desirable security properties, but it's |
28 |
not being done simply because "Fedora did it". |
29 |
|
30 |
> |
31 |
> Thanks and kind regards |
32 |
> |
33 |
> //Peter |
34 |
> |
35 |
|
36 |
Best, |
37 |
sam |