Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upUse SHA256 or SHA512 for all PGP signatures #1116
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Aug 12, 2015
Member
Does anyone know if there's any reason to prefer SHA512 over SHA256 (either in general or for specific purposes)? For example, the Tor Project signs their TBB archives with SHA512, but I'm not sure whether that's because it's more secure or faster[1] or both.
|
Does anyone know if there's any reason to prefer SHA512 over SHA256 (either in general or for specific purposes)? For example, the Tor Project signs their TBB archives with SHA512, but I'm not sure whether that's because it's more secure or faster[1] or both. |
marmarek
added this to the Release 3.1 milestone
Sep 2, 2015
marmarek
added
the
T: task
label
Sep 2, 2015
rootkovska
added
task
and removed
T: task
labels
Sep 2, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Oct 8, 2015
Member
Abstract: We present in this article a freestart collision example for SHA-1, i.e., a collision for its internal compression function. This is the first practical break of the full SHA-1, reaching all 80 out of 80 steps, while only 10 days of computation on a 64 GPU cluster were necessary to perform the attack. [...]
|
added a commit
to marmarek/qubes-builder
that referenced
this issue
Oct 12, 2015
added a commit
to marmarek/qubes-builder-rpm
that referenced
this issue
Oct 28, 2015
marmarek
modified the milestones:
Release 3.1 updates,
Release 3.1
Feb 8, 2016
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Jul 31, 2016
Member
@rootkovska, would you be willing to switch to SHA256 or SHA512 for signing QSBs and canaries? Your signatures on those are the only two things left.
|
@rootkovska, would you be willing to switch to SHA256 or SHA512 for signing QSBs and canaries? Your signatures on those are the only two things left. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Aug 5, 2016
Member
@rootkovska you can simply add digest-algo SHA256 to ~/.gnupg/gpg.conf in your qubes-secpack accessing VM (or appropriate split-gpg backend).
|
@rootkovska you can simply add |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Sure, I shall switch for the next secpack canary. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Done, see my sig on the QSB 25. |
andrewdavidwong commentedAug 12, 2015
•
edited by rootkovska
Edited 1 time
-
rootkovska
edited Sep 8, 2016 (most recent)
SHA256 or SHA512 should be used as the digest algorithm for PGP signatures on all of the following: