W dniu wto, 24.10.2017 o godzinie 13∶56 +0200, użytkownik Chí-Thanh Christopher Nguyễn napisał: > Michał Górny schrieb: > > Oh, and most notably, the speed loss will be mostly visible to users. > > An attacker would have to compute the additional hashes only > > if the fastest hash already matched, i.e. rarely. Users will have to > > compute them all the time. > > That is currently the case with portage, but not an inevitable consequence of > having 3 hash functions in the Manifest. Portage could be made to check only > one or two of them (even by default), giving the tie-breaking ability to > those who need it, and speeding up things for those who don't.
No, it can't. The specification (GLEP 59) requires it to check all hashes. -- Best regards, Michał Górny