recent discussion regarding 'checksums'

Matt McCutchen matt at mattmccutchen.net
Sun Sep 26 10:43:27 MDT 2010


On Fri, 2010-09-24 at 00:31 -0400, grarpamp wrote:
> [rsync -c fails to copy a file with an MD5 collision]

Yes, right now "rsync -c" is not good if an attacker has had the
opportunity to plant files on the destination and you want to make sure
the files get updated properly, but that's an uncommon use case, so I
don't consider the issue urgent (i.e., I'm not going to fix it myself).
There is a Fedora bug about it:

https://bugzilla.redhat.com/show_bug.cgi?id=483056

You could file a bug on https://bugzilla.samba.org/ if you like.

-- 
Matt



More information about the rsync mailing list