{"thread":{"id":"32273","subject":"Exploiting SHA1's \"XOR weakness\" allows for faster hash calculation","startedAt":"2012-12-05T09:19:43Z","lastAt":"2012-12-06T08:11:29Z","messageCount":4,"participants":["Sebastian Schuberth","Marko Kreen","Theodore Ts'o"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"204515","messageId":"k9n3jd$akg$1@ger.gmane.org","threadId":"32273","inReplyTo":null,"subject":"Exploiting SHA1's \"XOR weakness\" allows for faster hash calculation","fromName":"Sebastian Schuberth","fromEmail":"sschuberth@gmail.com","sentAt":"2012-12-05T09:19:43Z","receivedAt":"2012-12-05T09:19:43Z","isPatch":false,"sender":{"key":"sschuberth@gmail.com","avatar":"https://avatars.githubusercontent.com/u/349154?v=4"},"body":"Hi,\n\nto say it in advance: I do not want to trigger any bogus security \ndiscussion here. Instead, I believe the findings from [1] allow for an \nup to 20% faster SHA1 calculation, if my brief reading of the \npresentation is correct. Any opinions on integration this optimization \ninto Git?\n\n[1] https://hashcat.net/p12/js-sha1exp_169.pdf\n\n-- \nSebastian Schuberth\n"},{"id":"204516","messageId":"CACMqXC+jfkvj_ot0x6La6gOHypuXE-LX41V04_yQdZ+gytSDDw@mail.gmail.com","threadId":"32273","inReplyTo":"k9n3jd$akg$1@ger.gmane.org","subject":"Re: Exploiting SHA1's \"XOR weakness\" allows for faster hash calculation","fromName":"Marko Kreen","fromEmail":"markokr@gmail.com","sentAt":"2012-12-05T12:26:46Z","receivedAt":"2012-12-05T12:26:46Z","isPatch":false,"sender":{"key":"markokr@gmail.com","avatar":null},"body":"On Wed, Dec 5, 2012 at 11:19 AM, Sebastian Schuberth\n<sschuberth@gmail.com> wrote:\n> to say it in advance: I do not want to trigger any bogus security discussion\n> here. Instead, I believe the findings from [1] allow for an up to 20% faster\n> SHA1 calculation, if my brief reading of the presentation is correct. Any\n> opinions on integration this optimization into Git?\n>\n> [1] https://hashcat.net/p12/js-sha1exp_169.pdf\n\nPretty cool find.  Although it's not actual cryptographic weakness, it does\nshow some gaps in designers thinking - as there are simple optimizations\navailable to crackers but not users.\n\nIt does seem unusable for real implementation - the 20% win\nis available only after the data is processed properly once.\nThen after changing the data a little, you can calculate next\nhash faster.\n\nThere still small possibility that there is way to optimize W calculation\nfor the first run, but it does seem really hard, and even impossible\nwhile trying to keep the cache usage small.\n\n-- \nmarko\n"},{"id":"204533","messageId":"20121205172011.GH18885@thunk.org","threadId":"32273","inReplyTo":"k9n3jd$akg$1@ger.gmane.org","subject":"Re: Exploiting SHA1's \"XOR weakness\" allows for faster hash calculation","fromName":"Theodore Ts'o","fromEmail":"tytso@mit.edu","sentAt":"2012-12-05T17:20:11Z","receivedAt":"2012-12-05T17:20:11Z","isPatch":false,"sender":{"key":"tytso@mit.edu","avatar":"https://avatars.githubusercontent.com/u/51416?v=4"},"body":"On Wed, Dec 05, 2012 at 10:19:43AM +0100, Sebastian Schuberth wrote:\n> \n> to say it in advance: I do not want to trigger any bogus security\n> discussion here. Instead, I believe the findings from [1] allow for\n> an up to 20% faster SHA1 calculation, if my brief reading of the\n> presentation is correct. Any opinions on integration this\n> optimization into Git?\n> \n> [1] https://hashcat.net/p12/js-sha1exp_169.pdf\n\nIt's only useful if you are trying to do brute-force password\ncracking, where the password is being hashed in a very specific way.\n(If for example the password was replicated N times in the input\nbuffer for SHA-1, instead of keeping the padding constant in the rest\nof theinput buffer, this particular optimization would't apply.)\n\nIn any case, it's not at all applicable for general purpose checksum\ncalculations, and hence wouldn't apply to git.\n\nRegards,\n\n\t\t\t\t\t\t- Ted\n"},{"id":"204554","messageId":"CAHGBnuN1AwjAFeJMizXu9e-iD3n1GuWMNm9OPxCH7t1BcGz8Rw@mail.gmail.com","threadId":"32273","inReplyTo":"20121205172011.GH18885@thunk.org","subject":"Re: Exploiting SHA1's \"XOR weakness\" allows for faster hash calculation","fromName":"Sebastian Schuberth","fromEmail":"sschuberth@gmail.com","sentAt":"2012-12-06T08:11:29Z","receivedAt":"2012-12-06T08:11:29Z","isPatch":false,"sender":{"key":"sschuberth@gmail.com","avatar":"https://avatars.githubusercontent.com/u/349154?v=4"},"body":"On Wed, Dec 5, 2012 at 6:20 PM, Theodore Ts'o <tytso@mit.edu> wrote:\n\n> It's only useful if you are trying to do brute-force password\n> cracking, where the password is being hashed in a very specific way.\n> (If for example the password was replicated N times in the input\n> buffer for SHA-1, instead of keeping the padding constant in the rest\n> of theinput buffer, this particular optimization would't apply.)\n>\n> In any case, it's not at all applicable for general purpose checksum\n> calculations, and hence wouldn't apply to git.\n\nThanks for the explanation.\n\n-- \nSebastian Schuberth\n"}]}