On Friday, March 19, 2021, 21:30:03, Bill Stewart wrote:
> SHA1 for hashing isn't a security issue. (The purpose for storing the
> hashes is to detect changes, not for encryption.)
In this specific case (ensuring that the signed setup wasn't modified), SHA-1 is used for security, and thus likely ineffective at detecting that with specially crafted files.
--
< Jernej Simončič ><><><><><
https://eternallybored.org/ >
Technologie don't transfer.
-- Conrad's Conundrum (Stentson's Law)