Gentoo Archives: gentoo-dev

From: "Chí-Thanh Christopher Nguyễn" <chithanh@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Manifest2 hashes, take n+1-th: 3 hashes for the tie-breaker case
Date: Tue, 24 Oct 2017 11:56:14
Message-Id: 73ce6032-2c65-676c-cf5c-233810555df5@gentoo.org
In Reply to: Re: [gentoo-dev] Manifest2 hashes, take n+1-th: 3 hashes for the tie-breaker case by "Michał Górny"
1 Michał Górny schrieb:
2 > Oh, and most notably, the speed loss will be mostly visible to users.
3 > An attacker would have to compute the additional hashes only
4 > if the fastest hash already matched, i.e. rarely. Users will have to
5 > compute them all the time.
6
7 That is currently the case with portage, but not an inevitable consequence of
8 having 3 hash functions in the Manifest. Portage could be made to check only
9 one or two of them (even by default), giving the tie-breaking ability to
10 those who need it, and speeding up things for those who don't.
11
12
13 Best regards,
14 Chí-Thanh Christopher Nguyễn

Replies