[tor-bugs] #9930 [Website]: SHA-1 is weak: Use better hash to generate signatures
Tor Bug Tracker & Wiki
blackhole at torproject.org
Tue Dec 16 10:56:44 UTC 2014
#9930: SHA-1 is weak: Use better hash to generate signatures
-------------------------+-----------------
Reporter: mkral | Owner:
Type: defect | Status: new
Priority: normal | Milestone:
Component: Website | Version:
Resolution: | Keywords:
Actual Points: | Parent ID:
Points: |
-------------------------+-----------------
Comment (by mkral):
Replying to [comment:1 nickm]:
> If the signatures on the website start using a better hash, which
versions of gnupg will be able to check them? I support this, so long as
we're not going to start depending on a very rare gnupg version.
According to Gnupg changelog, read-only support for SHA-256 hash, SHA-384
and SHA-512 hashes was added in in version 1.3.2 (2003-05-27). Full
(read/write) support for the SHA-256 hash has been added in version 1.3.3
(2003-10-10)
In version Gnupg 1.4.10 (2009-09-02). The default hash algorithm
preferences has changed to prefer SHA-256 over SHA-1.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9930#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list