Bug#944696: python-apt: relies on MD5 internally to download packages

2019-11-14 Thread AreYouLoco?
I am no expert but on my opinion a temporary fix would be to bring back MD5 for the time being and then fixing/extending python-apt functions to check for more secure sums like SHA* first and then if not found fallback to MD5. But just for the backwards-compatibility since MD5 are know to be

Bug#944696: python-apt: relies on MD5 internally to download packages

2019-11-13 Thread Cyril Brulebois
Cyril Brulebois (2019-11-14): > Looking at the current (as of 2019-11-14 00:27:00 UTC) indices for > buster/updates on security.debian.org, one can only see SHA256 entries > in Release and Packages files, which is likely the reason for > python-apt's explosion. I've asked #debian-ftp to add

Bug#944696: python-apt: relies on MD5 internally to download packages

2019-11-13 Thread Cyril Brulebois
Package: python-apt Version: 1.8.4 Severity: serious Justification: some people want to get rid of MD5Sum in indices Hi, While debugging a live-wrapper (lwr) failure that started occurring (literally) overnight, I ended up discovering it was triggered by the intel-microcode package's getting a