Bernd Zeimetz <be...@bzed.de> writes: > Philipp Kern wrote: >> On 2010-03-03, Wouter Verhelst <wou...@debian.org> wrote: >>> This is where I disagree. When a checksum algorithm is compromised (and >>> MD5 *is* compromised), things only ever get worse, not better. Indeed, >>> MD5 preimage attacks are pretty hard *today*. But switching to something >>> more secure in preparation for the day when MD5 will be easily cracked >>> by every script kiddo around is *not* overkill. >> >> Sure, but to be honest, not even all packages managed to generate md5sums >> 'till now (with some quite core, omnipresent packages missing) so it seems >> out >> of scope for squeeze. Maybe squeeze+1. > > I think its about time to require to generate checksums for packages and make > all packages which do not do so RC buggy.
If a checksum file becomes required then it really is not the job of the package to build it. Instead dpkg should generate one and include it automatically. And given the widespread generation of md5sum files that really should be automated anyway. This would go nicely with changing the checksum algorithm. Just prepare a patch for dpkg to generate a sha256sum file automatically when it builds a deb and then packages can stop generating md5sum files over time. MfG Goswin -- To UNSUBSCRIBE, email to debian-devel-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/87aaumzjiy....@frosties.localdomain