4 ms·
Not sure how well thought out this decision is considering that SHA-1 has resisted preimage attacks for almost a decade longer than the SHA-2 family (since it i
by brl 17y ago
Not sure how well thought out this decision is considering that SHA-1 has resisted preimage attacks for almost a decade longer than the SHA-2 family (since it is that much older).
Re-keying hundreds of developers as well as the entire Debian infrastructure seems like a pretty extreme reaction to a problem that doesn't actually exist.
- dfranke 17y agoI would be very surprised if there were a tractable preimage attack against either algorithm in the next hundred years.