Hacker News new | ask | show | jobs
by noselasd 2991 days ago
The issue is that if these files are distributed elsewhere by 3. parties, it is trivial for those 3. parties change and compromise the files, but still make the files produce the same MD5 sum.
2 comments

If you think a preimage attack against MD5 is "trivial" you should demonstrate it. People would be very interested in this because no one has managed to do it yet.

Creating two files with the same MD5 is a very different beast from creating a file with the same MD5 as an arbitrary pre-existing file. These third parties would need to have colluded with the DragonFly developers to make what you're proposing possible.

Wouldn't it be easier for said third parties to just distribute changed checksum?
Then it would also be trivial to discover if you go and look up the sums at the official site.