Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-dev
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-dev@g.o
From: Hanno Böck <hanno@g.o>
Subject: Re: Notification about MD5 support
Date: Thu, 21 Sep 2006 17:54:14 +0200
Am Donnerstag, 21. September 2006 16:49 schrieb Vlastimil Babka:
> Although the "more secure than MD5" part is now questionable, I suppose
> the "directly available in python" part still holds?

From "What's new in python 2.5"

13.3 The hashlib package 
 A new hashlib module, written by Gregory P. Smith, has been added to replace 
the md5 and sha modules. hashlib adds support for additional secure hashes 
(SHA-224, SHA-256, SHA-384, and SHA-512). When available, the module uses 
OpenSSL for fast platform optimized implementations of algorithms. 
 The old md5 and sha modules still exist as wrappers around hashlib to 
preserve backwards compatibility. The new module's interface is very close to 
that of the old modules, but not identical. The most significant difference 
is that the constructor functions for creating new hashing objects are named 
differently.


I think sha256/512 is the only thing that makes sense at the moment, as it 
most probably will stay secure for quite a while and we don't have real 
alternatives. So imho use sha256, get rid of everything else, because that 
rarely improves security, and wait for the nist to define something new 
(which will happen, but probably take some years from now).

cu,

Hanno
Attachment:
pgpnt7bZITUcq.pgp (PGP signature)
Replies:
Re: Notification about MD5 support
-- Chris White
References:
Notification about MD5 support
-- Marius Mauch
Re: Notification about MD5 support
-- Mike Frysinger
Re: Notification about MD5 support
-- Vlastimil Babka
Navigation:
Lists: gentoo-dev: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: Notification about MD5 support
Next by thread:
Re: Notification about MD5 support
Previous by date:
Re: Re: Delay in approval of new developers
Next by date:
Re: Notification about MD5 support


Updated Jun 17, 2009

Summary: Archive of the gentoo-dev mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.