sentinel icon indicating copy to clipboard operation
sentinel copied to clipboard

Releases page lists only MD5 checksums

Open nbros652 opened this issue 5 years ago • 0 comments

Webpage: https://github.com/sentinel-official/sentinel/releases

Issue: The only checksums listed for releases are MD5 checksums. While this may be sufficient for verifying against file corruption, it is really insufficient for verifying against file tampering. The generation of an MD5 checksum collision is not difficult and does not necessarily result in significant changes in file size.

Suggested Change: Include checksums that are less susceptible to collisions. Perhaps, it would be better to include a SHA256 checksum.

nbros652 avatar Dec 05 '19 03:12 nbros652