Hacker News new | ask | show | jobs
by simplehuman 3368 days ago
Sha1 collisions...
1 comments

what's wrong with doing <insert hash function>?
Making a hash of the release is just a small part of it (and is the first part of what they are doing).

The trick is to be confident that you're getting the same hash as everyone else - and that's what requiring a proof that it be added to a CT logs gives you some level of assurance about.