duplicity-talk
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Duplicity-talk] Feature request/discussion: Store identical files o


From: Kenneth Loafman
Subject: Re: [Duplicity-talk] Feature request/discussion: Store identical files only once
Date: Wed, 25 Jun 2008 06:20:34 -0500
User-agent: Thunderbird 2.0.0.14 (X11/20080505)

Peter Schuller wrote:
> I generally like the idea. The problem I see is security. I'd be fine usng 
> this on e.g. my own home directory. But more general use can be quite 
> sensitive. One may allow for accidental hash collisions being sufficiently 
> unlikely that you can ignore the problem; but in the presence of malicious 
> intent you are also relying on the security of the hash algorithm - 
> especially given the various ways that information of the sort that "user X 
> has a file Y with checksum Z" might possibly be leaked to third parties.

The hash collision and malicious intent problems can be fairly easily
avoided by storing a pair of hashes (say MD5 and SHA1) which both have
to match, along with a checksum for the meta-data record.

...Ken


Attachment: signature.asc
Description: OpenPGP digital signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]