>>>>> On Wed, 06 Apr 2022, Jason A Donenfeld wrote: > Why? Then we're dependent on two things, either of which could break, > rather than one.
See? If either of these should happen, then we'll be happy that we still have both hashes in our Manifest files. OTOH, if that argument is not relavant because the probability of both is close to zero, then (from a security POV) it doesn't matter which of the two hashes we remove. Ulrich
signature.asc
Description: PGP signature