Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Manifest2 hashes, take n+1-th: 3 hashes for the tie-breaker case
Date: Tue, 24 Oct 2017 13:26:00
Message-Id: 1508851547.25623.0.camel@gentoo.org
In Reply to: Re: [gentoo-dev] Manifest2 hashes, take n+1-th: 3 hashes for the tie-breaker case by "Chí-Thanh Christopher Nguyễn"
1 W dniu wto, 24.10.2017 o godzinie 13∶56 +0200, użytkownik Chí-Thanh
2 Christopher Nguyễn napisał:
3 > Michał Górny schrieb:
4 > > Oh, and most notably, the speed loss will be mostly visible to users.
5 > > An attacker would have to compute the additional hashes only
6 > > if the fastest hash already matched, i.e. rarely. Users will have to
7 > > compute them all the time.
8 >
9 > That is currently the case with portage, but not an inevitable consequence of
10 > having 3 hash functions in the Manifest. Portage could be made to check only
11 > one or two of them (even by default), giving the tie-breaking ability to
12 > those who need it, and speeding up things for those who don't.
13
14 No, it can't. The specification (GLEP 59) requires it to check all hashes.
15
16 --
17 Best regards,
18 Michał Górny

Replies

Subject Author
Re: [gentoo-dev] Manifest2 hashes, take n+1-th: 3 hashes for the tie-breaker case Allan Wegan <allanwegan@××××××××××.de>