Re: [RFC] adding support for md5
- From
- Chris Wedgwood <cw@f00f.org>
- Date
- Aug 21, 2006, 20:44 UTC
- Message-ID
- <20060821204430.GA2700@tuatara.stupidest.org>
- In-Reply-To
- <Pine.LNX.4.64.0608191339010.11811@g5.osdl.org>
On Sat, Aug 19, 2006 at 01:50:32PM -0700, Linus Torvalds wrote:
> I can see the point of configurable hashes, but it would be for a > stronger hash than sha1, not for a (much) weaker one.
Why any configuration option at all? What in practice does it really buy?
If someone (eventually) wants to do something malicious (which right now requires some effort and would probably not go undetected) there are probably easier ways to achieve this (like posting a patch with a non-obvious subtle side-effect).