A possible step toward integrity measurement for Fedora
A possible step toward integrity measurement for Fedora
Posted Jan 9, 2021 9:22 UTC (Sat) by Wol (subscriber, #4433)In reply to: A possible step toward integrity measurement for Fedora by rahulsundaram
Parent article: A possible step toward integrity measurement for Fedora
> > I may be very wrong here. Am I right in thinking that Fedora and Red Hat still rely largely on SHA-1 and MD5 for verification? If so, addidional signatures may help as an additional validation step.
> This hasn't been true in well over a decade
And to what extend is it relevant? How easy is it to produce a signature collision with those hashes? Sorry I haven't been following it particularly, but producing a collision is harder than just breaking the hash. Or have they now got automated "hack a collision" malware out there now?
Cheers,
Wol
