Ulrich Mueller: >> So you are suggesting to not migrate at all or severely break the >> workflow because someone might forge _working code_ with a specific >> SHA1? There is no efficient algorithm for that afaik, those are just >> about finding _any_ collision and even then it takes considerable >> resources that can be used to break gentoo in much easier ways. > > Weakness of SHA-1 is discussed since several years, and it is > generally recommended that one should slowly move away from it. > Therefore I would find it strange if we (in 2014!) deployed a system > relying on it, while in our present Manifest files SHA-1 was already > abandoned long time ago, in favour of more secure hashes. It looks > like a move in the wrong direction. >
You are only talking about hashes, not about practical security.
