On Wed, 03 Mar 2010, Wouter Verhelst wrote: > In this day and age of completely and utterly broken MD5[0], I think we > should stop providing these files, and maybe provide something else > instead. Like, I dunno, shasums? Or perhaps gpgsigs? But stop providing > md5sums.
Is there any reason why we can't just modify dpkg-deb to create DEBIAN/md5sums and DEBIAN/sha512sums and get archive coverage relatively quickly, automatically, as things get rebuilt? Don Armstrong -- We cast this message into the cosmos. [...] We are trying to survive our time so we may live into yours. We hope some day, having solved the problems we face, to join a community of Galactic Civilizations. This record represents our hope and our determination and our goodwill in a vast and awesome universe. -- Jimmy Carter on the Voyager Golden Record http://www.donarmstrong.com http://rzlab.ucr.edu -- To UNSUBSCRIBE, email to debian-devel-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/20100305194048.gm28...@volo.donarmstrong.com