20 Aug 15, 09:49AM
(19 Aug 15, 06:38PM)damien Wrote: https://www.schneier.com/blog/archives/2...roken.htmlThat's old news. That is the theoretical vulnerability that I mentioned. 10 years later, there are still no practical attacks that work for SHA1, even if you have a "little" money. And anyway, it's no extra effort to include SHA1 hash for those who don't have the tools for other hashes.
It's breakable by anybody having a "little" money... We don't know who controls sourceforge. And today, cloud computing is quite easily available. No need to get paranoid, but as a common matter of principle, let's avoid them.
And anyway, we don't need to worry when using sha256 isn't more complicated.