1 |
On 11/04/2015 09:56 AM, Andrew Savchenko wrote: |
2 |
> On Sun, 1 Nov 2015 14:53:20 +0100 hasufell wrote: |
3 |
>>>> You shouldn't use rsync anymore, it is inherently insecure. The git |
4 |
>>>> tree is _properly_ gpg signed so you can verify it's correctness. |
5 |
>>>> |
6 |
>>>> With the following portage configuration/hooks, any user can run the |
7 |
>>>> tree directly from git: |
8 |
>>>> https://github.com/hasufell/portage-gentoo-git-config |
9 |
>>> |
10 |
>>> More secure by fetching metadata cache via rsync ? |
11 |
>>> Better by running egencache after each sync ? |
12 |
>>> I don't think so. |
13 |
>>> |
14 |
>> |
15 |
>> Yes it is. |
16 |
> |
17 |
> No, it is not. The whole git tree is insecure and no better than |
18 |
> rsync or CVS in terms of data security because SHA1 is vulnerable. |
19 |
> |
20 |
|
21 |
Another one who is confusing _any_ collision with _preimage attack_ ;) |