New issue
Advanced search Search tips

Issue 695904 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Mar 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug

Blocking:
issue 690573



Sign in to add a comment

Can we use sha2 instead of md5 in pack_firmware.sh versions?

Project Member Reported by sjg@chromium.org, Feb 24 2017

Issue description

This script produces a version file with md5 checksums of the images. Can or should we use sha2 instead? It would be more secure.

https://cs.corp.google.com/search/?q=f:pack_firmware.sh+md5&type=cs
 

Comment 1 by sjg@chromium.org, Feb 24 2017

Blocking: 690573

Comment 2 by derat@chromium.org, Feb 24 2017

And I didn't know about the SHA-1 collision when I suggested this in the review, even. :-P

Comment 3 by hungte@chromium.org, Feb 25 2017

Those MD5 sum were just for people to help checking what they have put, and we don't really use it when unpacking, so I see no security impact, especially the ebuild Manifest already has multiple hash checksum.

People may try to repack on chroot, on DUT (cros release image), or on deskop (ubuntu or debian) md5 was selected because it's more widely available. If you are changing the algorithm you have to find one that is compatible for all environments.

Comment 4 by sjg@chromium.org, Mar 14 2017

Owner: sjg@chromium.org
Status: WontFix (was: Untriaged)
OK it seems like it is OK as is. Thank you.

Sign in to add a comment