Let's avoid using md5 as checksum

Blair Zajac blair at orcaware.com
Fri Feb 15 23:55:12 PST 2008


William Allen Simpson wrote:
> On 2/15/08, Eric Hall <opendarwin.org at darkart.com> wrote:
> And that is the only relevant issue.  Something that a hash cannot solve.
> 
> As long as we ONLY use hashes generated by the distfile author, located
> on the distfile site, and NEVER generate our own, we'll be fine.

We should be fine if they PGP sign the file and then we get the hashes from that?

Blair

-- 
Blair Zajac, Ph.D.
CTO, OrcaWare Technologies
<blair at orcaware.com>
Subversion training, consulting and support
http://www.orcaware.com/svn/


More information about the macports-dev mailing list