From owner-freebsd-security@FreeBSD.ORG Fri Aug 15 10:02:21 2008 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 61137106567E; Fri, 15 Aug 2008 10:02:21 +0000 (UTC) (envelope-from des@des.no) Received: from tim.des.no (tim.des.no [194.63.250.121]) by mx1.freebsd.org (Postfix) with ESMTP id 1319A8FC13; Fri, 15 Aug 2008 10:02:21 +0000 (UTC) (envelope-from des@des.no) Received: from ds4.des.no (des.no [84.49.246.2]) by smtp.des.no (Postfix) with ESMTP id 1CC802049; Fri, 15 Aug 2008 11:44:38 +0200 (CEST) Received: by ds4.des.no (Postfix, from userid 1001) id 02C1E844AB; Fri, 15 Aug 2008 11:44:37 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: "Ivan Voras" References: <9bbcef730808131923o1ce56bc7i32b52ca884a54c@mail.gmail.com> Date: Fri, 15 Aug 2008 11:44:37 +0200 In-Reply-To: <9bbcef730808131923o1ce56bc7i32b52ca884a54c@mail.gmail.com> (Ivan Voras's message of "Thu, 14 Aug 2008 04:23:40 +0200") Message-ID: <86k5eiwr22.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.0.60 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org Subject: Re: MD5 man page X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 15 Aug 2008 10:02:21 -0000 "Ivan Voras" writes: > "MD5 has not yet (1999-02-11) been broken [...]" > Shouldn't it be updated or at least the date of the statement moved to > somewhere in this century? It should be updated, MD5 has been further weakened since then. This is why the ports tree now uses SHA256 checksums in addition to MD5. See http://en.wikipedia.org/wiki/MD5 for additional details. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no