Re: md5sums files
On Wed, 03 Mar 2010, Wouter Verhelst wrote:
> In this day and age of completely and utterly broken MD5[0], I think we
> should stop providing these files, and maybe provide something else
> instead.  Like, I dunno, shasums? Or perhaps gpgsigs? But stop providing
> md5sums.
Is there any reason why we can't just modify dpkg-deb to create
DEBIAN/md5sums and DEBIAN/sha512sums and get archive coverage
relatively quickly, automatically, as things get rebuilt?
 
Don Armstrong
-- 
We cast this message into the cosmos. [...] We are trying to survive
our time so we may live into yours. We hope some day, having solved
the problems we face, to join a community of Galactic Civilizations.
This record represents our hope and our determination and our goodwill
in a vast and awesome universe.
 -- Jimmy Carter on the Voyager Golden Record
http://www.donarmstrong.com              http://rzlab.ucr.edu
Reply to: