4 ms·
What's wrong with just doing SHA1?
by gary4gar 10y ago
What's wrong with just doing SHA1?
- simplehuman 10y agoSha1 collisions...
- aanm1988 10y agowhat's wrong with doing <insert hash function>?
- aeijdenberg 10y agoMaking a hash of the release is just a small part of it (and is the first part of what they are doing). The trick is to be confident that you're getting the same hash as everyone else - and that's what requiring a proof that it be added to a CT logs gives you some level of assurance about.
- khedoros1 10y agoIf the binary you're downloading might have been modified, how do you know that the hash you're checking against hasn't been as well?