Replace uses of SHA1 with SHA256

Bug #1698536 reported by Jelmer Vernooij
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Breezy
Triaged
Medium
Unassigned

Bug Description

SHA1 is insecure (https://www.schneier.com/blog/archives/2005/02/sha1_broken.html); we should replace all uses of it in Bazaar with something more secure. SHA256?

Jelmer Vernooij (jelmer)
tags: added: new-format
Jelmer Vernooij (jelmer)
tags: added: next-format
Jelmer Vernooij (jelmer)
Changed in brz:
milestone: 3.0.0 → none
Jelmer Vernooij (jelmer)
tags: added: bzr-format
Revision history for this message
Aaron Bentley (abentley) wrote :

David Timothy Strauss, (who seems to be a Breezy fan), thinks that sha512 should be used instead of sha256: https://medium.com/@davidtstrauss/stop-using-sha-256-6adbb55c608

Jelmer Vernooij (jelmer)
Changed in brz:
importance: High → Medium
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.