Op do 10 mei 2018 01:26 schreef Leonid Isaev via arch-general < arch-general@xxxxxxxxxxxxx>: > On Wed, May 09, 2018 at 09:30:51PM +0200, Neven Sajko wrote: > > I would just like to note that SHA-2 hashes are inferior to Keccak and > > to BLAKE2. So better not to spend effort migrating to SHA-2. > > Strength of various SHA hashes is a different topic. My only point was that > relying on md5 these days is like having no hashes at all or using the > source > filename as a hash... > Which is (still) pretty much the point of these hashes. With pacman these are *not* very important. The hashes are there for a quick check if the download is complete. Integrity is a job for PGP. Mvg, Guus Snijders >