various

Michal Jaegermann michal at harddata.com
Fri Mar 18 21:46:03 UTC 2005


On Fri, Mar 18, 2005 at 02:55:44PM -0500, Ignacio Vazquez-Abrams wrote:
> 
> FC4t1 uses sha1sum for some reason, not md5sum.

Possibly because there was recently a successful crypographic attack
against SHA-1. :-)  See
http://www.schneier.com/crypto-gram-0503.html
http://theory.csail.mit.edu/~yiqun/shanote.pdf

Don't worry.  It does not look like that this will be a practical
threat for signatures on distribution images, or many other things,
for quite a while yet.

   Michal




More information about the test mailing list