sha1 and rmd160

Joshua Root jmr at macports.org
Fri Apr 6 06:12:20 PDT 2012


On 2012-4-6 23:07 , Arno Hautala wrote:
> On 2012-04-06, Craig Treleaven <ctreleaven at cogeco.ca> wrote:
>>
>> Just curious, why two checkums?  Is one not sufficient?
> 
> One thought would be that while one hash algorithm may exhibit a flaw
> that allows arbitrary changes to the payload without altering the
> hash, it's extremely unlikely that two hashes would be affected in the
> same way.

That's pretty much it.

> I don't think MacPorts actually verifies every hash that is provided
> in the Portfile.

It does.

- Josh


More information about the macports-dev mailing list