[tor-bugs] #9930 [Website]: SHA-1 is weak: Use better hash to generate signatures

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Dec 16 10:56:44 UTC 2014


#9930: SHA-1 is weak: Use better hash to generate signatures
-------------------------+-----------------
     Reporter:  mkral    |      Owner:
         Type:  defect   |     Status:  new
     Priority:  normal   |  Milestone:
    Component:  Website  |    Version:
   Resolution:           |   Keywords:
Actual Points:           |  Parent ID:
       Points:           |
-------------------------+-----------------

Comment (by mkral):

 Replying to [comment:1 nickm]:
 > If the signatures on the website start using a better hash, which
 versions of gnupg will be able to check them? I support this, so long as
 we're not going to start depending on a very rare gnupg version.

 According to Gnupg changelog, read-only support for SHA-256 hash,  SHA-384
 and SHA-512 hashes was added in in version 1.3.2 (2003-05-27). Full
 (read/write) support for the SHA-256 hash has been added in version 1.3.3
 (2003-10-10)

 In version Gnupg 1.4.10 (2009-09-02). The default hash algorithm
 preferences has changed to prefer SHA-256 over SHA-1.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9930#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list