Re: [vox] MD5 Checksums and Public Downloading
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [vox] MD5 Checksums and Public Downloading
On Thu, 2002-05-16 at 00:13, Peter Jay Salzman wrote:
> begin Micah Cowan <micah@cowan.name>
> > Can somebody explain to me what the point is for generating checksums
> > for verifying downloaded files? If the primary purpose is security,
> > what is to prevent a malicious person, either "man-in-the-middle" or
> > someone who tampered with a repository, from generating a new MD5 sum
> > for you to verify? What exactly does the checksum prevent?
>
> i think the point here is a preponderance of evidence. md5sums are
> usually published in a variety of places, and it would be hard for said
> malicious person to tamper with the whole bunch of them.
H'm... I must have been seeing them in different places than you,
then. I sometimes see MD5 sums simply distributed side-by-side with the
software they checksum; in fact, it was on seeing this that I posted to
the group (no, I don't remember what software it was).
> > If the primary purpose is simply to guard against corrupt data, I'd
> > hardly think it worth the effort, considering I very rarely get
> > corrupted data.
>
> you're probably right here, but i think the keyword here is "i" (or
> rather "you"). other people may not be so lucky. certainly back in the
> 80's when i was using a modem to transfer \/\/arez, errors were pretty
> common place. modems didn't have error detection like they do today.
People have pointed out that it's useful for very large files, which I
wasn't really considering, and can certainly understand. I was mostly
interested in its intended purpose for security, really - as I'm having
trouble seeing how that purpose is served.
-Micah
_______________________________________________
vox mailing list
vox@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox
|