Gentoo Archives: gentoo-dev

From: "Chí-Thanh Christopher Nguyễn" <chithanh@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] ChangeLog
Date: Wed, 04 Nov 2015 16:33:25
Message-Id: 563A3341.3040504@gentoo.org
In Reply to: Re: [gentoo-dev] ChangeLog by hasufell
1 hasufell schrieb:
2 > On 11/04/2015 09:56 AM, Andrew Savchenko wrote:
3 >> No, it is not. The whole git tree is insecure and no better than
4 >> rsync or CVS in terms of data security because SHA1 is vulnerable.
5 >>
6 > Another one who is confusing _any_ collision with _preimage attack_ ;)
7
8 While Andrew's view is very pessimistic here, yours is decidedly optimistic.
9
10 There is no known computationally feasible preimage attack against MD5,
11 still that hash function is broken in serious ways with attacks already
12 having real-world consequences.
13
14 It would be quite naïve to assume that SHA1 will remain secure until a
15 preimage attack is found.
16
17
18 Best regards,
19 Chí-Thanh Christopher Nguyễn

Replies

Subject Author
Re: [gentoo-dev] ChangeLog hasufell <hasufell@g.o>