BitcoinTalk

md5?

BitcoinTalk
#1
From:
fresno
Subject:
md5?
Date:
I don't seem to be able to find any md5s for your code downloads. Is it just me, or are there none?

BitcoinTalk
#2
From:
Mionione
Subject:
Re: md5?
Date:
md5 checksums are still widely used but not secure
BitcoinTalk
#3
From:
Mionione
Subject:
Re: md5?
Date:
md5 is evil, two differents files can have the same md5 checksum (http://www.coresecurity.com/content/md5-harmful)
but unfortunately people still use it ;(
BitcoinTalk
#4
From:
knightmb
Subject:
Re: md5?
Date:
md5 is evil, two differents files can have the same md5 checksum (http://www.coresecurity.com/content/md5-harmful)
but unfortunately people still use it ;(

They can, but the odds that you'll get useful exploit code that just happens to be that collision are still insanely high.
BitcoinTalk
#5
From:
lachesis
Subject:
Re: md5?
Date:
Nah, it's insanely easy nowadays. Have you seen evilize?

http://www.mscs.dal.ca/~selinger/md5collision/
BitcoinTalk
#6
From:
d1337r
Subject:
Re: md5?
Date:
Yeah... In earlier days, you could easily set an 8-letter Upper-Lower-Digit password and be sure no one will be interested in cracking it (which he will do for 30 days minimum). Now, we have Playstation 3's and cloud services, and cracking that MD5 is a matter of minutes or hours. Now i'll have to change every my password to something stronger.

BTW, SMF FTW, cause it uses SHA-256 instead of MD5.
BitcoinTalk
#7
From:
fresno
Subject:
Re: md5?
Date:
Yeah, I guess SHA-256 will be good enough. ;-)



BitcoinTalk
#8
From:
bitcoinex
Subject:
gpg!
Date:
Hashes are good but it's already time to start doing gpg-signatures to tarball. Suffice it now to hack the site or even deception to obtain control over the wiki, put "fresh" version of the client and everything collapses.
BitcoinTalk
#9
From:
satoshi
Subject:
Re: md5?
Date:
For future reference, here's my public key.  It's the same one that's been there since the bitcoin.org site first went up in 2008.  Grab it now in case you need it later.

http://www.bitcoin.org/Satoshi_Nakamoto.asc