[Project_owners] Stronger Hash Support for Secure Installations and Updates
Douglas E. Warner
silfreed at silfreed.net
Mon Jun 1 12:02:54 PDT 2009
Ever since released  our file release system  (including secure updates
and installations of .xpi files) we've planned on improving the support of
hashes. We didn't originally realize that md5 was no longer on the list of
hashes , and with sha1 having its own share of problems recently, the need
for stronger hashes was increased.
So finally we have dropped support for md5 as well and support only the
stronger hash mechanisms (sha1, sha256, sha384, and sha512). We still
auto-detect the hash type by the length of the hash submitted in the file
management tool, so the procedure is exactly the same. Any existing md5
hashes are still in our system and presented by our secure install links but
are considered deprecated.
Douglas E. Warner <silfreed at silfreed.net> Site Developer
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 189 bytes
Desc: OpenPGP digital signature
More information about the Project_owners