Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-26 Thread Thomas Deutschmann
On 2021-07-25 08:27, Michał Górny wrote: On Sun, 2021-07-25 at 01:12 +0200, Thomas Deutschmann wrote: I don't understand. Isn't it the same motion we put down just 2 months ago [1]? Or is this something new? If this isn't something new, what has changed since May [2]? Apparently it has not be

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-25 Thread Rich Freeman
On Sun, Jul 25, 2021 at 11:23 AM Ulrich Mueller wrote: > > We can reiterate when there are indications that SHA512 would be broken. > (Then again, the same applies to BLAKE2B.) Unless both are broken at the same time you'd also have the advantage of not having to try to scramble to figure out whe

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-25 Thread Ulrich Mueller
> On Sun, 25 Jul 2021, Roy Bamford wrote: > I'm in the "if it's not broken don't fix it" school. +1 I don't see a strong argument to remove SHA512, so leave things as they are for now. We can reiterate when there are indications that SHA512 would be broken. (Then again, the same applies to

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-25 Thread Luca Barbato
On 24/07/21 17:16, Michał Górny wrote: > Hi, everyone. > > I've been asked to repost the idea of removing SHA512 hash from > Manifests, effectively limiting them to BLAKE2B. > > The 'old' set of Gentoo hashes including SHA512 went live in July 2012. > In November 2017, we have decided to remove t

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-25 Thread Andreas K. Huettel
Am Samstag, 24. Juli 2021, 17:16:23 CEST schrieb Michał Górny: > Hi, everyone. > > I've been asked to repost the idea of removing SHA512 hash from > Manifests, effectively limiting them to BLAKE2B. Just keep things as they are for now. Even reading this bike^H^H^H^Hthread is more effort than the

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-25 Thread Roy Bamford
On 2021.07.25 00:12, Thomas Deutschmann wrote: > Hi, > > I don't understand. Isn't it the same motion we put down just 2 months > > ago [1]? Or is this something new? > > If this isn't something new, what has changed since May [2]? > > To remember: Currently we have two different hashes for eve

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-25 Thread Jonas Stein
Hi, Back during the 2017 discussion, Infra came to the conclusion that we're going to keep SHA512 for a transition period, then remove it, and stay with a single hash algorithm. In my opinion, we have kept it long enough. WDYT? As far I remember we agreed to keep two different hashes. The id

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-25 Thread Eddie Chapman
On 24/07/2021 16:16, Michał Górny wrote: Hi, everyone. I've been asked to repost the idea of removing SHA512 hash from Manifests, effectively limiting them to BLAKE2B. The 'old' set of Gentoo hashes including SHA512 went live in July 2012. In November 2017, we have decided to remove the two oth

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-25 Thread Toralf Förster
On 7/24/21 5:16 PM, Michał Górny wrote: Back during the 2017 discussion, Infra came to the conclusion that we're going to keep SHA512 for a transition period, then remove it, and stay with a single hash algorithm. I'm just curious if Infra in 2021 still wants only 1 hash algo? In my opinion,

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-24 Thread Michał Górny
On Sun, 2021-07-25 at 01:12 +0200, Thomas Deutschmann wrote: > Hi, > > I don't understand. Isn't it the same motion we put down just 2 months > ago [1]? Or is this something new? > > If this isn't something new, what has changed since May [2]? Apparently it has not been 'put down' because it ca

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-24 Thread Michał Górny
On Sat, 2021-07-24 at 17:15 -0400, Joshua Kinard wrote: > On 7/24/2021 11:16, Michał Górny wrote: > > Hi, everyone. > > > > I've been asked to repost the idea of removing SHA512 hash from > > Manifests, effectively limiting them to BLAKE2B. > > > > The 'old' set of Gentoo hashes including SHA512

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-24 Thread Thomas Deutschmann
Hi, I don't understand. Isn't it the same motion we put down just 2 months ago [1]? Or is this something new? If this isn't something new, what has changed since May [2]? To remember: Currently we have two different hashes for every distfile. If we are going to throw this data away, we shoul

Re: [gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-24 Thread Joshua Kinard
On 7/24/2021 11:16, Michał Górny wrote: > Hi, everyone. > > I've been asked to repost the idea of removing SHA512 hash from > Manifests, effectively limiting them to BLAKE2B. > > The 'old' set of Gentoo hashes including SHA512 went live in July 2012. > In November 2017, we have decided to remove

[gentoo-dev] [RFC] Removing SHA512 hash from Manifests

2021-07-24 Thread Michał Górny
Hi, everyone. I've been asked to repost the idea of removing SHA512 hash from Manifests, effectively limiting them to BLAKE2B. The 'old' set of Gentoo hashes including SHA512 went live in July 2012. In November 2017, we have decided to remove the two other hashes and add BLAKE2B in their stead.