MD5 is vulnerable...

Randy Zagar <[email protected]>
Newsgroups gmane.linux.rpm.metadata
Message-ID <[email protected]>
It's been known for at least a few months that there are 
block-transposition attacks that can cause collision problems with MD5.  
This means that it is theoretically possible to construct a new 
(possibly hostile) file that has the same MD5 checksum as a file that we 
trust...

Bruce Schneier also reports on his weblog that SHA-1 has been 
compromised.  The difficulty of cracking SHA-1 checksums has been 
reduced from "virtually impossible" to "extremely difficult".

In light of this, I'd like to suggest that the xml metadata be modified 
to include BOTH the MD5 and SHA-1 checksums in the metadata files...  
Even if someone manages to compromise one signature, it'll be 
geometrically more difficult to compromise both signatures simultaneously...

-RZ
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.