-
Bug
-
Resolution: Unresolved
-
Normal
-
None
On Picard's download page (https://picard.musicbrainz.org/downloads/) the MD5 hashes for each files are listed. Unfortunately MD5 is cryptographically broken due to hash collisions. (See: https://en.wikipedia.org/wiki/MD5#Security)
Proposal: Provide SHA256 hash, or even better: PGP signature
- has related issue
-
PICARD-1934 GPG key used for signing is DSA 1024bit (unusable for verification)
- Closed