Ignore:
Timestamp:
10/18/2021 10:47:42 AM (3 years ago)
Author:
Xi Ruoyao <xry111@…>
Branches:
11.1, 11.2, 11.3, 12.0, 12.1, kea, ken/TL2024, ken/inkscape-core-mods, ken/tuningfonts, lazarus, lxqt, plabs/newcss, plabs/python-mods, python3.11, qt5new, rahul/power-profiles-daemon, renodr/vulkan-addition, trunk, upgradedb, xry111/intltool, xry111/llvm18, xry111/soup3, xry111/test-20220226, xry111/xf86-video-removal
Children:
dcf242f
Parents:
2ef4e24b
Message:

building-notes: MD5 can be used to detect stealth update

File:
1 edited

Legend:

Unmodified
Added
Removed
  • introduction/important/building-notes.xml

    r2ef4e24b r97ba425  
    113113
    114114    <para>MD5 is not cryptographically secure, so the md5sums are only
    115     provided for detecting random errors or truncations introduced during
    116     network transfer.  There is no <quote>100%</quote> secure way to make
     115    provided for detecting unmalicious changes to the file content.  For
     116    example, an error or truncation introduced during network transfer, or
     117    a <quote>stealth</quote> update to the package from the upstream
     118    (updating the content of a released tarball instead of making a new
     119    release properly).</para>
     120
     121    <para>There is no <quote>100%</quote> secure way to make
    117122    sure the genuity of the source files.  Assuming the upstream is managing
    118123    their website correctly (the private key is not leaked and the domain is
Note: See TracChangeset for help on using the changeset viewer.