Ulrich Mueller:
>> So you are suggesting to not migrate at all or severely break the
>> workflow because someone might forge _working code_ with a specific
>> SHA1? There is no efficient algorithm for that afaik, those are just
>> about finding _any_ collision and even then it takes considerable
>> resources that can be used to break gentoo in much easier ways.
> 
> Weakness of SHA-1 is discussed since several years, and it is
> generally recommended that one should slowly move away from it.
> Therefore I would find it strange if we (in 2014!) deployed a system
> relying on it, while in our present Manifest files SHA-1 was already
> abandoned long time ago, in favour of more secure hashes. It looks
> like a move in the wrong direction.
> 

You are only talking about hashes, not about practical security.

Reply via email to