Post
Topic
Board Development & Technical Discussion
Re: Please remove Bitcoin from Sourceforge.net
by
twobits
on 18/08/2011, 02:42:40 UTC
sha-1 was broken about six years ago now, and even if it was not, whatever has it being used could be  broken tomorrow.  So always better for something important to use two very different hashes. The link to those hashes is not obvious at all from the link to the downloads on the main page.  A link to them should be added.

SHA-1 is not broken. It is also highly unlikely it will go from where it stands now to completely broken and unusable for this purpose overnight. That said, I would be in favor of also signing a stronger hash. It is good to stay ahead.

It is broken.  Think it was in '05.  I remember it being a Chinese paper that showed this.   If really need be I can probably dig up the links.