vBulletin Search Engine Optimization
| |||||||
| Register | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| ||||
| > So no matter what you`ll do (as developers of OpenBSD) the question > came up one more time and I think some peoples should start looking for > alternative HASH-Algorithms used in the Ports. The distinfo files contain size as well as MD5, SHA1 and RMD160 hashes. From my tests (with make fetch, make checksum and make package) Size and SHA1 are checked. I would imagine that you would be hard pressed (I hate to say impossible, but it seems HIGHLY unlikely) to find a hashing weakness that could be exploited such that all 3 hashes and the file size were identical to a "known good" distinfo. Instead of spending time finding and implementing new hashes, the infrastructure need only check all the hashes instead of just SHA1 (or two of the three, even) & size. Looking through ports(7) and bsd.port.mk(5), I didn't find such an option, but it may already exist. - Seth > Links for Nessie: > http://www.cryptonessie.org/ > > Kind regards, > Sebastian Rother |
| Thread Tools | |
| Display Modes | |
| |