Page MenuHomePhabricator

Add img_sha256, related columns with SHA-256 hash of file
Open, LowPublic

Description

Image table's img_sha1 file is used to look for duplicate files at upload time. While known SHA-1 attacks can't be used to create a duplicate of an existing file, they can be used to create pairs or sets of files which will cause confusion, leading to recommendation to use SHA-256 instead.

Recommend:

  • add img_sha256 and related fields
  • populate hashes of old entries
  • adjust suitable internal and external APIs to take SHA-256 hashes as well as SHA-1 hashes

Event Timeline

brion created this task.Feb 24 2017, 7:16 PM
Restricted Application added projects: Multimedia, Commons. · View Herald TranscriptFeb 24 2017, 7:16 PM
MaxSem added a subscriber: MaxSem.Feb 24 2017, 8:30 PM
Ltrlg added a subscriber: Ltrlg.Feb 25 2017, 12:07 AM
Reedy moved this task from Unsorted to Add / Create on the Schema-change board.Apr 26 2017, 2:20 PM
MarkTraceur triaged this task as Low priority.Jul 10 2017, 3:21 PM
MarkTraceur moved this task from Untriaged to Triaged on the Multimedia board.