BugTraq
SHA-1 broken Feb 16 2005 12:56PM
Gadi Evron (gadi tehila gov il) (5 replies)
Re: SHA-1 broken Feb 17 2005 02:44PM
Jonathan G. Lampe (jonathan lampe standardnetworks com)
Re: SHA-1 broken Feb 17 2005 01:28AM
Steve Friedl (steve unixwiz net)
Re: SHA-1 broken Feb 17 2005 01:25AM
Robert Sussland (robert inkwood org) (1 replies)

On Feb 16, 2005, at 4:56 AM, Gadi Evron wrote:

> Now, we've all seen this coming for a while.
> http://www.schneier.com/blog/archives/2005/02/sha1_broken.html
>
> Where do we go from here?
>
We abandon the requirement of collision resistance. This is a strange
requirement, and is not supported by experience. Collision resistance
is not a "hard" problem in the sense that factoring large numbers or
computing discrete logs is hard. Collision resistance in deterministic
hash functions smells too much like generating entropy without secrets.
I have no reason to believe that careful analysis of *any* publicly
known deterministic many-to-one function will not allow me to produce a
collision, assuming I control all inputs into the function.

From my point of view, the issue is what weaker assumption do we
replace collision resistance with -- how about:

target collision resistance, with the "strength" of resistance equal to
the average advantage an attacker would gain in matching a fixed
target, as the target is averaged over all possible inputs in a measure
space? Then, producing "rare" messages which could be targeted would
not weaken the hash, as the probability of such messages occurring
would be low.

[ reply ]
Re: SHA-1 broken Feb 17 2005 10:42PM
dullien gmx de (2 replies)
Re: SHA-1 broken Feb 19 2005 05:24PM
Darren Reed (avalon caligula anu edu au) (1 replies)
Re: SHA-1 broken Feb 19 2005 05:41PM
dullien gmx de
Re: SHA-1 broken Feb 19 2005 01:22PM
Tollef Fog Heen (tfheen err no) (1 replies)
Re: SHA-1 broken Feb 20 2005 09:45AM
Denis Jedig (seclists syneticon de)
Re: SHA-1 broken Feb 17 2005 01:02AM
Michael Cordover (michael cordover gmail com) (3 replies)
Re: SHA-1 broken Feb 18 2005 02:22AM
Dan Harkless (bugtraq harkless org)
Re: SHA-1 broken Feb 17 2005 11:32PM
D.J. Capelis (djcapelisp yahoo com) (1 replies)
Re: SHA-1 broken Feb 19 2005 03:37AM
Michael Cordover (michael cordover gmail com)
Re: SHA-1 broken Feb 17 2005 10:39PM
dullien gmx de
Re: SHA-1 broken Feb 16 2005 11:27PM
Kent Borg (kentborg borg org)


 

Privacy Statement
Copyright 2010, SecurityFocus