Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provide SHA3 hashes on downloads page of getmonero.org #3041

Closed
b-g-goodell opened this issue Dec 31, 2017 · 4 comments
Closed

Provide SHA3 hashes on downloads page of getmonero.org #3041

b-g-goodell opened this issue Dec 31, 2017 · 4 comments
Labels

Comments

@b-g-goodell
Copy link

Since SHA256 is vulnerable to length extension attacks, the downloads page of getmonero.org should include at least the SHA3 hash for each file.

@b-g-goodell
Copy link
Author

I'm aware that a more complete "canonical" list is available, but I don't think the sha256 hash should be the one on getmonero.org

@mberry
Copy link

mberry commented Jan 1, 2018

The hashing is to check for file integrity, not security. If getmonero/repo is compromised changing the hash is trivial. Verifying the signature determines authenticity and ensures security, the particular hash function used doesn't really matter, though it's always good to have more.

@ghost
Copy link

ghost commented Jan 3, 2018

Whichever the outcome is, this issue is more related to the monero-site repository.

@dEBRUYNE-1
Copy link
Contributor

@b-g-goodell Please reopen this issue on the monero-site repository.

+invalid

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants