{"thread":{"id":"52586","subject":"SHA-1 chosen-prefix colission attack","startedAt":"2020-01-07T17:39:47Z","lastAt":"2020-01-08T07:30:44Z","messageCount":3,"participants":["Kevin Daudt","Santiago Torres Arias","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"389400","messageId":"20200107173111.GB923852@alpha","threadId":"52586","inReplyTo":null,"subject":"SHA-1 chosen-prefix colission attack","fromName":"Kevin Daudt","fromEmail":"me@ikke.info","sentAt":"2020-01-07T17:31:11Z","receivedAt":"2020-01-07T17:39:47Z","isPatch":false,"sender":{"key":"me@ikke.info","avatar":"https://avatars.githubusercontent.com/u/135698?v=4"},"body":"Researchers published new advances in creating collisions in SHA-1\nhashes: https://sha-mbles.github.io/\n\n> As a side result, this shows that it now costs less than 100k USD to\n> break cryptography with a security level of 64 bits (i.e. to compute\n> 264 operations of symmetric cryptography).\n\nKevin\n\n"},{"id":"389425","messageId":"20200107203147.r33c5plp5g7pmxmj@LykOS.localdomain","threadId":"52586","inReplyTo":"20200107173111.GB923852@alpha","subject":"Re: SHA-1 chosen-prefix colission attack","fromName":"Santiago Torres Arias","fromEmail":"santiago@nyu.edu","sentAt":"2020-01-07T20:31:48Z","receivedAt":"2020-01-07T20:55:33Z","isPatch":false,"sender":{"key":"santiago@nyu.edu","avatar":"https://avatars.githubusercontent.com/u/3579933?v=4"},"body":"> > As a side result, this shows that it now costs less than 100k USD to\n> > break cryptography with a security level of 64 bits (i.e. to compute\n> > 264 operations of symmetric cryptography).\n\nJust to clarify:\n\n    As a stopgap measure, the collision-detection library of Stevens and Shumow [SS17]\n    can be used to detect attack attempts (it successfully detects our attack).\n\nAt the end of section 7.0,\n\nCheers\n-Santiago\n"},{"id":"389455","messageId":"20200108073042.GD1675456@coredump.intra.peff.net","threadId":"52586","inReplyTo":"20200107203147.r33c5plp5g7pmxmj@LykOS.localdomain","subject":"Re: SHA-1 chosen-prefix colission attack","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2020-01-08T07:30:42Z","receivedAt":"2020-01-08T07:30:44Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Tue, Jan 07, 2020 at 03:31:48PM -0500, Santiago Torres Arias wrote:\n\n> > > As a side result, this shows that it now costs less than 100k USD to\n> > > break cryptography with a security level of 64 bits (i.e. to compute\n> > > 264 operations of symmetric cryptography).\n> \n> Just to clarify:\n> \n>     As a stopgap measure, the collision-detection library of Stevens and Shumow [SS17]\n>     can be used to detect attack attempts (it successfully detects our attack).\n> \n> At the end of section 7.0,\n\nAnd if anyone is curious, you can test your build of Git against their\nsample files by running:\n\n  $ t/helper/test-tool sha1 <messageA\n  fatal: SHA-1 appears to be part of a collision attack: 8ac60ba76f1999a1ab70223f225aefdc78d4ddc0\n\nUnfortunately you can't test with actual Git objects, because their\nchosen-prefixes don't have object headers. They do estimate that a\nclassical collision is down to ~11k USD to compute, so maybe we'll see\none eventually. :)\n\n-Peff\n"}]}