{"thread":{"id":"64861","subject":"The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","startedAt":"2026-01-23T20:16:59Z","lastAt":"2026-01-25T14:22:10Z","messageCount":10,"participants":["Klaus Sembritzki","Jeff King","Marc Branchaud","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"534577","messageId":"CADMnYXDDbVBwZgETsFhwkOyn8cM8QU4+YQs2rRfTac6ec49-5A@mail.gmail.com","threadId":"64861","inReplyTo":null,"subject":"The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Klaus Sembritzki","fromEmail":"klausem@gmail.com","sentAt":"2026-01-23T20:16:46Z","receivedAt":"2026-01-23T20:16:59Z","isPatch":false,"sender":{"key":"klausem@gmail.com","avatar":null},"body":"Dear all,\n\nsee for yourself:\n\n$ # xy: 1337\n$ echo xy | sha256sum\n$ 3b2fc206fd92be3e70843a6d6d466b1f400383418b3c16f2f0af89981f1337f3\n\n$ # za: acbad\n$ echo za | sha256sum\n$ 28832ea947ea9588ff3acbad546b27fd001a875215beccf0e5e4eee51cc81a2e\n\n$ # My initials (ks): 1aa\n$ echo ks | sha256sum\n$ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n\n$ # 50566750337\n$ echo thinking | sha256sum\n$ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n\nLess strange results, but I still wonder if this is random, as\nexpected after reading this: https://crypto.stackexchange.com/a/12840\n\n$ # It was bad AF BC:\n$ # bc, badfaf\n$ echo bc | sha256sum\n$ bc18cd878fc136926875bcb4bddc7f3badfaf4298f5dd1a9fd4c1b9692b624fc\n\n$ # 439247560, 1532557\n$ echo vw | sha256sum\n$ 439247560f158e6c80ea9b43c3345b4468ccf6fb1532557b1bab8908ad8b075a\n\nI do not need my name attached to these examples, even though I am 1aa.\n\nCheers,\nKlaus Sembritzki\n"},{"id":"534579","messageId":"20260123210643.GA2728629@coredump.intra.peff.net","threadId":"64861","inReplyTo":"CADMnYXDDbVBwZgETsFhwkOyn8cM8QU4+YQs2rRfTac6ec49-5A@mail.gmail.com","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-01-23T21:06:43Z","receivedAt":"2026-01-23T21:06:45Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n\n> $ # My initials (ks): 1aa\n> $ echo ks | sha256sum\n> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n> \n> $ # 50566750337\n> $ echo thinking | sha256sum\n> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n\nOh man, I've got deadbeef!\n\n  $ echo jk35252822 | sha256sum\n  33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n\nWhat could it all mean?\n\n-Peff\n"},{"id":"534586","messageId":"e54a3865-b75b-4c28-b3a3-62fcb02bbfb5@xiplink.com","threadId":"64861","inReplyTo":"20260123210643.GA2728629@coredump.intra.peff.net","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Marc Branchaud","fromEmail":"marcnarc@xiplink.com","sentAt":"2026-01-23T21:57:43Z","receivedAt":"2026-01-23T21:57:48Z","isPatch":false,"sender":{"key":"marcnarc@xiplink.com","avatar":"https://avatars.githubusercontent.com/u/14980203?v=4"},"body":"Deep Crypto is obviously far more insidious than anyone expected.  How \ncould we have not realized that our SHA IDs were so subversive?\n\nI mean, ab6edf73?  Really?  Who ever thought that was even remotely OK?\n\nWe need to immediately replace our SHA IDs with sequences of \nsemantically-neutral symbols.  I suggest we use non-hex integers to \nrepresent the value of each byte (hexadecimal letters being the work of \nthe devil -- I mean, \"hex\" is right there in the name!), and use \nsomething neutral like □ (U25A1) as a separator (but only by default; \nthis symbol must be configurable).  For example:\n\n\t12deadbeef45 --> 12□222□173□190□239□45\n\n(I realize that numbers themselves can carry deeply harmful baggage, but \nI'm hoping the integers from 1 to 255 aren't too offensive.  OK, maybe \ntolerating 111 is asking too much...)\n\nI only hope we can spare future generations from our modern deprivations.\n\n\t\tM.\n\n\nOn 2026-01-23 14:06, Jeff King wrote:\n> On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n> \n>> $ # My initials (ks): 1aa\n>> $ echo ks | sha256sum\n>> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n>>\n>> $ # 50566750337\n>> $ echo thinking | sha256sum\n>> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n> \n> Oh man, I've got deadbeef!\n> \n>    $ echo jk35252822 | sha256sum\n>    33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n> \n> What could it all mean?\n> \n> -Peff\n> \n\n"},{"id":"534587","messageId":"xmqq8qdogdmu.fsf@gitster.g","threadId":"64861","inReplyTo":"20260123210643.GA2728629@coredump.intra.peff.net","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-01-23T22:36:41Z","receivedAt":"2026-01-23T22:36:44Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Jeff King <peff@peff.net> writes:\n\n> On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n>\n>> $ # My initials (ks): 1aa\n>> $ echo ks | sha256sum\n>> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n>> \n>> $ # 50566750337\n>> $ echo thinking | sha256sum\n>> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n>\n> Oh man, I've got deadbeef!\n>\n>   $ echo jk35252822 | sha256sum\n>   33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n>\n> What could it all mean?\n\nSorry, but I have to admit that I completely lack humor receptor\ncells.\n\n\n\n"},{"id":"534589","messageId":"CADMnYXD9BOGyBNX+7pecow=by8n_+Zhh1EJ0RYWd1c1qujrsmg@mail.gmail.com","threadId":"64861","inReplyTo":"xmqq8qdogdmu.fsf@gitster.g","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Klaus Sembritzki","fromEmail":"klausem@gmail.com","sentAt":"2026-01-23T23:30:24Z","receivedAt":"2026-01-23T23:30:37Z","isPatch":false,"sender":{"key":"klausem@gmail.com","avatar":null},"body":"1. The brute-forced hash\n\n>  Sorry, but I have to admit that I completely lack humor receptor\n\nThat is a pity, because the brute-forced hash contains \"codoodikk\",\nwhich reads as \"code-dude and dikk\".\n\n33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\ncco1jgdebihg0deflefjmigleilonmfkmnjmknnoikiklcodoodikkb0cncfoifk\n\n2. Jeff King's real hash\n\necho jk | sha256sum\n720daff2aefd2b3457cbd597509b0fa399e258444302c2851f8d3cdd8ad781eb\n720 = 2*360 = 0\n\n3. Junio C Hamano's real hash\n\necho jch | sha256sum\nc666df2af21b29a6b2c7f3b9deddda805f2ed8dcd3c72a6fbf38f6c729e2c98a\n666\n\nOn Fri, Jan 23, 2026 at 11:36 PM Junio C Hamano <gitster@pobox.com> wrote:\n>\n> Jeff King <peff@peff.net> writes:\n>\n> > On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n> >\n> >> $ # My initials (ks): 1aa\n> >> $ echo ks | sha256sum\n> >> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n> >>\n> >> $ # 50566750337\n> >> $ echo thinking | sha256sum\n> >> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n> >\n> > Oh man, I've got deadbeef!\n> >\n> >   $ echo jk35252822 | sha256sum\n> >   33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n> >\n> > What could it all mean?\n>\n> Sorry, but I have to admit that I completely lack humor receptor\n> cells.\n>\n>\n>\n"},{"id":"534591","messageId":"20260124072814.GA3455597@coredump.intra.peff.net","threadId":"64861","inReplyTo":"xmqq8qdogdmu.fsf@gitster.g","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2026-01-24T07:28:14Z","receivedAt":"2026-01-24T07:28:21Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Jan 23, 2026 at 02:36:41PM -0800, Junio C Hamano wrote:\n\n> Jeff King <peff@peff.net> writes:\n> \n> > On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n> >\n> >> $ # My initials (ks): 1aa\n> >> $ echo ks | sha256sum\n> >> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n> >> \n> >> $ # 50566750337\n> >> $ echo thinking | sha256sum\n> >> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n> >\n> > Oh man, I've got deadbeef!\n> >\n> >   $ echo jk35252822 | sha256sum\n> >   33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n> >\n> > What could it all mean?\n> \n> Sorry, but I have to admit that I completely lack humor receptor\n> cells.\n\nProbably because it was not that funny. :)\n\nThe original message seemed to be looking for Numerology-style meanings\nin random data. I wasn't sure if it was serious or not, but I could not\nresist either playing along (if not) or trolling (if so).\n\nBut here's my deadbeef brute-force program for fun.\n\n-Peff\n\n-- >8 --\n#include <stdio.h>\n#include <string.h>\n#include <openssl/evp.h>\n\nint main(int argc, const char **argv)\n{\n\tconst char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n\tconst EVP_MD *algo = EVP_sha256();\n\tEVP_MD_CTX *ctx = EVP_MD_CTX_new();\n\n\tEVP_DigestInit_ex(ctx, algo, NULL);\n\twhile (*++argv)\n\t\tEVP_DigestUpdate(ctx, *argv, strlen(*argv));\n\n\tfor (unsigned i = 0; ; i++) {\n\t\tchar buf[16];\n\t\tchar *p;\n\t\tunsigned char digest[32];\n\t\tEVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n\n\t\tp = buf + sizeof(buf);\n\t\tfor (unsigned v = i; v; v /= 10)\n\t\t\t*--p = '0' + (v % 10);\n\t\tEVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n\t\tEVP_DigestUpdate(copy, \"\\n\", 1);\n\t\tEVP_DigestFinal_ex(copy, digest, NULL);\n\t\tEVP_MD_CTX_free(copy);\n\t\tif (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n\t\t\tprintf(\"%d\\n\", i);\n\t}\n}\n"},{"id":"534594","messageId":"CADMnYXA6_uCZU42NR2vFKM9uhfaWOdu0tkzPi6Ya8WW2rzknGg@mail.gmail.com","threadId":"64861","inReplyTo":"20260124072814.GA3455597@coredump.intra.peff.net","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Klaus Sembritzki","fromEmail":"klausem@gmail.com","sentAt":"2026-01-24T09:25:51Z","receivedAt":"2026-01-24T09:26:03Z","isPatch":false,"sender":{"key":"klausem@gmail.com","avatar":null},"body":"On Sat, Jan 24, 2026 at 8:28 AM Jeff King <peff@peff.net> wrote:\n>\n> On Fri, Jan 23, 2026 at 02:36:41PM -0800, Junio C Hamano wrote:\n>\n> > Jeff King <peff@peff.net> writes:\n> >\n> > > On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n> > >\n> > >> $ # My initials (ks): 1aa\n> > >> $ echo ks | sha256sum\n> > >> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n> > >>\n> > >> $ # 50566750337\n> > >> $ echo thinking | sha256sum\n> > >> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n> > >\n> > > Oh man, I've got deadbeef!\n> > >\n> > >   $ echo jk35252822 | sha256sum\n> > >   33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n> > >\n> > > What could it all mean?\n> >\n> > Sorry, but I have to admit that I completely lack humor receptor\n> > cells.\n>\n> Probably because it was not that funny. :)\n>\n> The original message seemed to be looking for Numerology-style meanings\n> in random data. I wasn't sure if it was serious or not, but I could not\n> resist either playing along (if not) or trolling (if so).\n>\n> But here's my deadbeef brute-force program for fun.\n>\n> -Peff\n>\n> -- >8 --\n> #include <stdio.h>\n> #include <string.h>\n> #include <openssl/evp.h>\n>\n> int main(int argc, const char **argv)\n> {\n>         const char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n>         const EVP_MD *algo = EVP_sha256();\n>         EVP_MD_CTX *ctx = EVP_MD_CTX_new();\n>\n>         EVP_DigestInit_ex(ctx, algo, NULL);\n>         while (*++argv)\n>                 EVP_DigestUpdate(ctx, *argv, strlen(*argv));\n>\n>         for (unsigned i = 0; ; i++) {\n>                 char buf[16];\n>                 char *p;\n>                 unsigned char digest[32];\n>                 EVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n>\n>                 p = buf + sizeof(buf);\n>                 for (unsigned v = i; v; v /= 10)\n>                         *--p = '0' + (v % 10);\n>                 EVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n>                 EVP_DigestUpdate(copy, \"\\n\", 1);\n>                 EVP_DigestFinal_ex(copy, digest, NULL);\n>                 EVP_MD_CTX_free(copy);\n>                 if (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n>                         printf(\"%d\\n\", i);\n>         }\n> }\n\nIncrementing the MSB instead of the LSB (indexing naturally starts\nwith 1 in that case) seems to improve the performance, and it finds\ndifferent solutions, if the program is terminated early.\nThe rationale is that there is autocorrelation in the observations,\nthough I cannot judge what that means in this concrete example. The\nspeedup is not that dramatic here, so SHA256 seems to be pretty\nrandom.\n\n#include <stdio.h>\n#include <string.h>\n#include <stdint.h>\n#include <openssl/evp.h>\n\n#ifdef POLYFILL\nEVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in)\n{\n    EVP_MD_CTX *out = EVP_MD_CTX_new();\n\n    if (out != NULL && !EVP_MD_CTX_copy_ex(out, in)) {\n        EVP_MD_CTX_free(out);\n        out = NULL;\n    }\n    return out;\n}\n#endif\n\n#define REVERTED_BIT(n, position, width) (((n & (1 << position)) >>\nposition) << (width - position - 2))\n\nuint32_t revert_bits(uint32_t n, uint32_t width) {\n    uint32_t result = 0;\n    for (uint32_t i = 0; i < width; ++i) {\n        result |= REVERTED_BIT(n, i, width);\n    }\n    return result;\n}\n\nint main(int argc, const char **argv)\n{\n    const char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n    const EVP_MD *algo = EVP_sha256();\n    EVP_MD_CTX *ctx = EVP_MD_CTX_new();\n\n    EVP_DigestInit_ex(ctx, algo, NULL);\n    while (*++argv)\n        EVP_DigestUpdate(ctx, *argv, strlen(*argv));\n\n    for (uint32_t n = 1; ; n++) {\n#if (COUNTER_WIDTH != 0)\n        uint32_t i = revert_bits(n, COUNTER_WIDTH);\n#else\n        uint32_t i = n;\n#endif\n        // printf(\"%u %u\\n\", n, i);\n        char buf[16];\n        char *p;\n        unsigned char digest[32];\n        EVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n\n        p = buf + sizeof(buf);\n        for (uint32_t v = i; v; v /= 10)\n            *--p = '0' + (v % 10);\n        EVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n        EVP_DigestUpdate(copy, \"\\n\", 1);\n        EVP_DigestFinal_ex(copy, digest, NULL);\n        EVP_MD_CTX_free(copy);\n        if (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n        {\n            printf(\"counter width: %2u | n: %10u | i: %10u\\n\",\nCOUNTER_WIDTH, n, i);\n            return 0;\n        }\n    }\n    return 1;\n}\n\ncc -DPOLYFILL -DCOUNTER_WIDTH=32 jk_evp.c -lssl -lcrypto -o jk_evp_msb_32\ncc -DPOLYFILL -DCOUNTER_WIDTH=31 jk_evp.c -lssl -lcrypto -o jk_evp_msb_31\ncc -DPOLYFILL -DCOUNTER_WIDTH=30 jk_evp.c -lssl -lcrypto -o jk_evp_msb_30\ncc -DPOLYFILL -DCOUNTER_WIDTH=29 jk_evp.c -lssl -lcrypto -o jk_evp_msb_29\ncc -DPOLYFILL -DCOUNTER_WIDTH=0 jk_evp.c -lssl -lcrypto -o jk_evp_0\ncounter width: 32 | n:  103832253 | i: 1588397616\ncounter width: 31 | n:   62413559 | i: 1003915120\ncounter width: 30 | n:  166340413 | i:  396135154\ncounter width: 29 | n:  137077701 | i:  171728193\ncounter width:  0 | n:  171728193 | i:  171728193\n"},{"id":"534607","messageId":"CADMnYXAF5VV9jKbxm1rduR-x96TFEso572zCAVOU-JoMpnX1tg@mail.gmail.com","threadId":"64861","inReplyTo":"CADMnYXA6_uCZU42NR2vFKM9uhfaWOdu0tkzPi6Ya8WW2rzknGg@mail.gmail.com","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Klaus Sembritzki","fromEmail":"klausem@gmail.com","sentAt":"2026-01-25T09:47:42Z","receivedAt":"2026-01-25T09:47:54Z","isPatch":false,"sender":{"key":"klausem@gmail.com","avatar":null},"body":"On Sat, Jan 24, 2026 at 10:25 AM Klaus Sembritzki <klausem@gmail.com> wrote:\n>\n> On Sat, Jan 24, 2026 at 8:28 AM Jeff King <peff@peff.net> wrote:\n> >\n> > On Fri, Jan 23, 2026 at 02:36:41PM -0800, Junio C Hamano wrote:\n> >\n> > > Jeff King <peff@peff.net> writes:\n> > >\n> > > > On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n> > > >\n> > > >> $ # My initials (ks): 1aa\n> > > >> $ echo ks | sha256sum\n> > > >> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n> > > >>\n> > > >> $ # 50566750337\n> > > >> $ echo thinking | sha256sum\n> > > >> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n> > > >\n> > > > Oh man, I've got deadbeef!\n> > > >\n> > > >   $ echo jk35252822 | sha256sum\n> > > >   33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n> > > >\n> > > > What could it all mean?\n> > >\n> > > Sorry, but I have to admit that I completely lack humor receptor\n> > > cells.\n> >\n> > Probably because it was not that funny. :)\n> >\n> > The original message seemed to be looking for Numerology-style meanings\n> > in random data. I wasn't sure if it was serious or not, but I could not\n> > resist either playing along (if not) or trolling (if so).\n> >\n> > But here's my deadbeef brute-force program for fun.\n> >\n> > -Peff\n> >\n> > -- >8 --\n> > #include <stdio.h>\n> > #include <string.h>\n> > #include <openssl/evp.h>\n> >\n> > int main(int argc, const char **argv)\n> > {\n> >         const char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n> >         const EVP_MD *algo = EVP_sha256();\n> >         EVP_MD_CTX *ctx = EVP_MD_CTX_new();\n> >\n> >         EVP_DigestInit_ex(ctx, algo, NULL);\n> >         while (*++argv)\n> >                 EVP_DigestUpdate(ctx, *argv, strlen(*argv));\n> >\n> >         for (unsigned i = 0; ; i++) {\n> >                 char buf[16];\n> >                 char *p;\n> >                 unsigned char digest[32];\n> >                 EVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n> >\n> >                 p = buf + sizeof(buf);\n> >                 for (unsigned v = i; v; v /= 10)\n> >                         *--p = '0' + (v % 10);\n> >                 EVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n> >                 EVP_DigestUpdate(copy, \"\\n\", 1);\n> >                 EVP_DigestFinal_ex(copy, digest, NULL);\n> >                 EVP_MD_CTX_free(copy);\n> >                 if (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n> >                         printf(\"%d\\n\", i);\n> >         }\n> > }\n>\n> Incrementing the MSB instead of the LSB (indexing naturally starts\n> with 1 in that case) seems to improve the performance, and it finds\n> different solutions, if the program is terminated early.\n> The rationale is that there is autocorrelation in the observations,\n> though I cannot judge what that means in this concrete example. The\n> speedup is not that dramatic here, so SHA256 seems to be pretty\n> random.\n>\n> #include <stdio.h>\n> #include <string.h>\n> #include <stdint.h>\n> #include <openssl/evp.h>\n>\n> #ifdef POLYFILL\n> EVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in)\n> {\n>     EVP_MD_CTX *out = EVP_MD_CTX_new();\n>\n>     if (out != NULL && !EVP_MD_CTX_copy_ex(out, in)) {\n>         EVP_MD_CTX_free(out);\n>         out = NULL;\n>     }\n>     return out;\n> }\n> #endif\n>\n> #define REVERTED_BIT(n, position, width) (((n & (1 << position)) >>\n> position) << (width - position - 2))\n>\n> uint32_t revert_bits(uint32_t n, uint32_t width) {\n>     uint32_t result = 0;\n>     for (uint32_t i = 0; i < width; ++i) {\n>         result |= REVERTED_BIT(n, i, width);\n>     }\n>     return result;\n> }\n>\n> int main(int argc, const char **argv)\n> {\n>     const char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n>     const EVP_MD *algo = EVP_sha256();\n>     EVP_MD_CTX *ctx = EVP_MD_CTX_new();\n>\n>     EVP_DigestInit_ex(ctx, algo, NULL);\n>     while (*++argv)\n>         EVP_DigestUpdate(ctx, *argv, strlen(*argv));\n>\n>     for (uint32_t n = 1; ; n++) {\n> #if (COUNTER_WIDTH != 0)\n>         uint32_t i = revert_bits(n, COUNTER_WIDTH);\n> #else\n>         uint32_t i = n;\n> #endif\n>         // printf(\"%u %u\\n\", n, i);\n>         char buf[16];\n>         char *p;\n>         unsigned char digest[32];\n>         EVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n>\n>         p = buf + sizeof(buf);\n>         for (uint32_t v = i; v; v /= 10)\n>             *--p = '0' + (v % 10);\n>         EVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n>         EVP_DigestUpdate(copy, \"\\n\", 1);\n>         EVP_DigestFinal_ex(copy, digest, NULL);\n>         EVP_MD_CTX_free(copy);\n>         if (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n>         {\n>             printf(\"counter width: %2u | n: %10u | i: %10u\\n\",\n> COUNTER_WIDTH, n, i);\n>             return 0;\n>         }\n>     }\n>     return 1;\n> }\n>\n> cc -DPOLYFILL -DCOUNTER_WIDTH=32 jk_evp.c -lssl -lcrypto -o jk_evp_msb_32\n> cc -DPOLYFILL -DCOUNTER_WIDTH=31 jk_evp.c -lssl -lcrypto -o jk_evp_msb_31\n> cc -DPOLYFILL -DCOUNTER_WIDTH=30 jk_evp.c -lssl -lcrypto -o jk_evp_msb_30\n> cc -DPOLYFILL -DCOUNTER_WIDTH=29 jk_evp.c -lssl -lcrypto -o jk_evp_msb_29\n> cc -DPOLYFILL -DCOUNTER_WIDTH=0 jk_evp.c -lssl -lcrypto -o jk_evp_0\n> counter width: 32 | n:  103832253 | i: 1588397616\n> counter width: 31 | n:   62413559 | i: 1003915120\n> counter width: 30 | n:  166340413 | i:  396135154\n> counter width: 29 | n:  137077701 | i:  171728193\n> counter width:  0 | n:  171728193 | i:  171728193\n\nI have to admit there is a bug in my previous code, it only works\ncorrectly for even numbers. It should have been:\n\n#define REVERTED_BIT(n, position, width) (((n & (1 << position)) >>\nposition) << (width - position - 2 + (width & 1)))\n\nuint32_t revert_bits(uint32_t n, uint32_t width) {\n    uint32_t result = 0;\n    for (uint32_t i = 0; i < width; ++i) {\n        result |= REVERTED_BIT(n, i, width);\n    }\n    return result;\n}\n\nThe actual performance measurements are:\ncounter width: 32 | n:  103832253 | i: 1588397616\ncounter width: 31 | n:  103832253 | i: 1588397616\ncounter width: 30 | n:  166340413 | i:  396135154\ncounter width: 29 | n:  166340413 | i:  396135154\ncounter width: 28 | n:  268041599 | i: 2281045247 # 2**28 is close to\nthe first finding when counting by incrementing the LSB, so this is\nslow.\ncounter width: 27: This does not find anything, because 2**27 is lower\nthan the first finding when counting by incrementing the LSB.\ncounter width:  0 | n:  171728193 | i:  171728193 #\nmath.log2(171728193) = 27.35555166834193\n"},{"id":"534609","messageId":"CADMnYXDBSTDHynvVcpfpU79V=BXNOksi1W0pHFRWgZBkqTf5Hw@mail.gmail.com","threadId":"64861","inReplyTo":"CADMnYXAF5VV9jKbxm1rduR-x96TFEso572zCAVOU-JoMpnX1tg@mail.gmail.com","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Klaus Sembritzki","fromEmail":"klausem@gmail.com","sentAt":"2026-01-25T11:25:51Z","receivedAt":"2026-01-25T11:26:03Z","isPatch":false,"sender":{"key":"klausem@gmail.com","avatar":null},"body":"On Sun, Jan 25, 2026 at 10:47 AM Klaus Sembritzki <klausem@gmail.com> wrote:\n>\n> On Sat, Jan 24, 2026 at 10:25 AM Klaus Sembritzki <klausem@gmail.com> wrote:\n> >\n> > On Sat, Jan 24, 2026 at 8:28 AM Jeff King <peff@peff.net> wrote:\n> > >\n> > > On Fri, Jan 23, 2026 at 02:36:41PM -0800, Junio C Hamano wrote:\n> > >\n> > > > Jeff King <peff@peff.net> writes:\n> > > >\n> > > > > On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n> > > > >\n> > > > >> $ # My initials (ks): 1aa\n> > > > >> $ echo ks | sha256sum\n> > > > >> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n> > > > >>\n> > > > >> $ # 50566750337\n> > > > >> $ echo thinking | sha256sum\n> > > > >> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n> > > > >\n> > > > > Oh man, I've got deadbeef!\n> > > > >\n> > > > >   $ echo jk35252822 | sha256sum\n> > > > >   33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n> > > > >\n> > > > > What could it all mean?\n> > > >\n> > > > Sorry, but I have to admit that I completely lack humor receptor\n> > > > cells.\n> > >\n> > > Probably because it was not that funny. :)\n> > >\n> > > The original message seemed to be looking for Numerology-style meanings\n> > > in random data. I wasn't sure if it was serious or not, but I could not\n> > > resist either playing along (if not) or trolling (if so).\n> > >\n> > > But here's my deadbeef brute-force program for fun.\n> > >\n> > > -Peff\n> > >\n> > > -- >8 --\n> > > #include <stdio.h>\n> > > #include <string.h>\n> > > #include <openssl/evp.h>\n> > >\n> > > int main(int argc, const char **argv)\n> > > {\n> > >         const char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n> > >         const EVP_MD *algo = EVP_sha256();\n> > >         EVP_MD_CTX *ctx = EVP_MD_CTX_new();\n> > >\n> > >         EVP_DigestInit_ex(ctx, algo, NULL);\n> > >         while (*++argv)\n> > >                 EVP_DigestUpdate(ctx, *argv, strlen(*argv));\n> > >\n> > >         for (unsigned i = 0; ; i++) {\n> > >                 char buf[16];\n> > >                 char *p;\n> > >                 unsigned char digest[32];\n> > >                 EVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n> > >\n> > >                 p = buf + sizeof(buf);\n> > >                 for (unsigned v = i; v; v /= 10)\n> > >                         *--p = '0' + (v % 10);\n> > >                 EVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n> > >                 EVP_DigestUpdate(copy, \"\\n\", 1);\n> > >                 EVP_DigestFinal_ex(copy, digest, NULL);\n> > >                 EVP_MD_CTX_free(copy);\n> > >                 if (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n> > >                         printf(\"%d\\n\", i);\n> > >         }\n> > > }\n> >\n> > Incrementing the MSB instead of the LSB (indexing naturally starts\n> > with 1 in that case) seems to improve the performance, and it finds\n> > different solutions, if the program is terminated early.\n> > The rationale is that there is autocorrelation in the observations,\n> > though I cannot judge what that means in this concrete example. The\n> > speedup is not that dramatic here, so SHA256 seems to be pretty\n> > random.\n> >\n> > #include <stdio.h>\n> > #include <string.h>\n> > #include <stdint.h>\n> > #include <openssl/evp.h>\n> >\n> > #ifdef POLYFILL\n> > EVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in)\n> > {\n> >     EVP_MD_CTX *out = EVP_MD_CTX_new();\n> >\n> >     if (out != NULL && !EVP_MD_CTX_copy_ex(out, in)) {\n> >         EVP_MD_CTX_free(out);\n> >         out = NULL;\n> >     }\n> >     return out;\n> > }\n> > #endif\n> >\n> > #define REVERTED_BIT(n, position, width) (((n & (1 << position)) >>\n> > position) << (width - position - 2))\n> >\n> > uint32_t revert_bits(uint32_t n, uint32_t width) {\n> >     uint32_t result = 0;\n> >     for (uint32_t i = 0; i < width; ++i) {\n> >         result |= REVERTED_BIT(n, i, width);\n> >     }\n> >     return result;\n> > }\n> >\n> > int main(int argc, const char **argv)\n> > {\n> >     const char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n> >     const EVP_MD *algo = EVP_sha256();\n> >     EVP_MD_CTX *ctx = EVP_MD_CTX_new();\n> >\n> >     EVP_DigestInit_ex(ctx, algo, NULL);\n> >     while (*++argv)\n> >         EVP_DigestUpdate(ctx, *argv, strlen(*argv));\n> >\n> >     for (uint32_t n = 1; ; n++) {\n> > #if (COUNTER_WIDTH != 0)\n> >         uint32_t i = revert_bits(n, COUNTER_WIDTH);\n> > #else\n> >         uint32_t i = n;\n> > #endif\n> >         // printf(\"%u %u\\n\", n, i);\n> >         char buf[16];\n> >         char *p;\n> >         unsigned char digest[32];\n> >         EVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n> >\n> >         p = buf + sizeof(buf);\n> >         for (uint32_t v = i; v; v /= 10)\n> >             *--p = '0' + (v % 10);\n> >         EVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n> >         EVP_DigestUpdate(copy, \"\\n\", 1);\n> >         EVP_DigestFinal_ex(copy, digest, NULL);\n> >         EVP_MD_CTX_free(copy);\n> >         if (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n> >         {\n> >             printf(\"counter width: %2u | n: %10u | i: %10u\\n\",\n> > COUNTER_WIDTH, n, i);\n> >             return 0;\n> >         }\n> >     }\n> >     return 1;\n> > }\n> >\n> > cc -DPOLYFILL -DCOUNTER_WIDTH=32 jk_evp.c -lssl -lcrypto -o jk_evp_msb_32\n> > cc -DPOLYFILL -DCOUNTER_WIDTH=31 jk_evp.c -lssl -lcrypto -o jk_evp_msb_31\n> > cc -DPOLYFILL -DCOUNTER_WIDTH=30 jk_evp.c -lssl -lcrypto -o jk_evp_msb_30\n> > cc -DPOLYFILL -DCOUNTER_WIDTH=29 jk_evp.c -lssl -lcrypto -o jk_evp_msb_29\n> > cc -DPOLYFILL -DCOUNTER_WIDTH=0 jk_evp.c -lssl -lcrypto -o jk_evp_0\n> > counter width: 32 | n:  103832253 | i: 1588397616\n> > counter width: 31 | n:   62413559 | i: 1003915120\n> > counter width: 30 | n:  166340413 | i:  396135154\n> > counter width: 29 | n:  137077701 | i:  171728193\n> > counter width:  0 | n:  171728193 | i:  171728193\n>\n> I have to admit there is a bug in my previous code, it only works\n> correctly for even numbers. It should have been:\n>\n> #define REVERTED_BIT(n, position, width) (((n & (1 << position)) >>\n> position) << (width - position - 2 + (width & 1)))\n>\n> uint32_t revert_bits(uint32_t n, uint32_t width) {\n>     uint32_t result = 0;\n>     for (uint32_t i = 0; i < width; ++i) {\n>         result |= REVERTED_BIT(n, i, width);\n>     }\n>     return result;\n> }\n>\n> The actual performance measurements are:\n> counter width: 32 | n:  103832253 | i: 1588397616\n> counter width: 31 | n:  103832253 | i: 1588397616\n> counter width: 30 | n:  166340413 | i:  396135154\n> counter width: 29 | n:  166340413 | i:  396135154\n> counter width: 28 | n:  268041599 | i: 2281045247 # 2**28 is close to\n> the first finding when counting by incrementing the LSB, so this is\n> slow.\n> counter width: 27: This does not find anything, because 2**27 is lower\n> than the first finding when counting by incrementing the LSB.\n> counter width:  0 | n:  171728193 | i:  171728193 #\n> math.log2(171728193) = 27.35555166834193\n\nAs an interim solution, it could make sense to leave small input\nunmodified, and to permute large texts to get rid of the natural\nlanguage manifold.\n"},{"id":"534611","messageId":"CADMnYXByAseQWja24JpfRaKGU1=v+d5b_J+EEXRV_iv1gEY3og@mail.gmail.com","threadId":"64861","inReplyTo":"CADMnYXDBSTDHynvVcpfpU79V=BXNOksi1W0pHFRWgZBkqTf5Hw@mail.gmail.com","subject":"Re: The SHA256 of \"xy\\n\" (ASCII, no CRLF) contains 1337, ACBAD in za, and I am 1aa","fromName":"Klaus Sembritzki","fromEmail":"klausem@gmail.com","sentAt":"2026-01-25T14:21:57Z","receivedAt":"2026-01-25T14:22:10Z","isPatch":false,"sender":{"key":"klausem@gmail.com","avatar":null},"body":"If vanilla-SHA256 continues to be used in vanilla-Git in the future, I\nsuggest that platforms like GitHub hash internally.\n\nOn Sun, Jan 25, 2026 at 12:25 PM Klaus Sembritzki <klausem@gmail.com> wrote:\n>\n> On Sun, Jan 25, 2026 at 10:47 AM Klaus Sembritzki <klausem@gmail.com> wrote:\n> >\n> > On Sat, Jan 24, 2026 at 10:25 AM Klaus Sembritzki <klausem@gmail.com> wrote:\n> > >\n> > > On Sat, Jan 24, 2026 at 8:28 AM Jeff King <peff@peff.net> wrote:\n> > > >\n> > > > On Fri, Jan 23, 2026 at 02:36:41PM -0800, Junio C Hamano wrote:\n> > > >\n> > > > > Jeff King <peff@peff.net> writes:\n> > > > >\n> > > > > > On Fri, Jan 23, 2026 at 09:16:46PM +0100, Klaus Sembritzki wrote:\n> > > > > >\n> > > > > >> $ # My initials (ks): 1aa\n> > > > > >> $ echo ks | sha256sum\n> > > > > >> $ 1aa44e718d5bc9b7ff2003dbbb6f154e16636d5c2128ffce4751af5124b65337\n> > > > > >>\n> > > > > >> $ # 50566750337\n> > > > > >> $ echo thinking | sha256sum\n> > > > > >> $ 50566750337beb9e98e553fd9196d10576f9eb0cbc6b66e2586b9d73af4f352f\n> > > > > >\n> > > > > > Oh man, I've got deadbeef!\n> > > > > >\n> > > > > >   $ echo jk35252822 | sha256sum\n> > > > > >   33f1a74529870456c56ad97c59cfed6bdeadbeef9b9bc3f4ff49bb203e36f96b\n> > > > > >\n> > > > > > What could it all mean?\n> > > > >\n> > > > > Sorry, but I have to admit that I completely lack humor receptor\n> > > > > cells.\n> > > >\n> > > > Probably because it was not that funny. :)\n> > > >\n> > > > The original message seemed to be looking for Numerology-style meanings\n> > > > in random data. I wasn't sure if it was serious or not, but I could not\n> > > > resist either playing along (if not) or trolling (if so).\n> > > >\n> > > > But here's my deadbeef brute-force program for fun.\n> > > >\n> > > > -Peff\n> > > >\n> > > > -- >8 --\n> > > > #include <stdio.h>\n> > > > #include <string.h>\n> > > > #include <openssl/evp.h>\n> > > >\n> > > > int main(int argc, const char **argv)\n> > > > {\n> > > >         const char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n> > > >         const EVP_MD *algo = EVP_sha256();\n> > > >         EVP_MD_CTX *ctx = EVP_MD_CTX_new();\n> > > >\n> > > >         EVP_DigestInit_ex(ctx, algo, NULL);\n> > > >         while (*++argv)\n> > > >                 EVP_DigestUpdate(ctx, *argv, strlen(*argv));\n> > > >\n> > > >         for (unsigned i = 0; ; i++) {\n> > > >                 char buf[16];\n> > > >                 char *p;\n> > > >                 unsigned char digest[32];\n> > > >                 EVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n> > > >\n> > > >                 p = buf + sizeof(buf);\n> > > >                 for (unsigned v = i; v; v /= 10)\n> > > >                         *--p = '0' + (v % 10);\n> > > >                 EVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n> > > >                 EVP_DigestUpdate(copy, \"\\n\", 1);\n> > > >                 EVP_DigestFinal_ex(copy, digest, NULL);\n> > > >                 EVP_MD_CTX_free(copy);\n> > > >                 if (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n> > > >                         printf(\"%d\\n\", i);\n> > > >         }\n> > > > }\n> > >\n> > > Incrementing the MSB instead of the LSB (indexing naturally starts\n> > > with 1 in that case) seems to improve the performance, and it finds\n> > > different solutions, if the program is terminated early.\n> > > The rationale is that there is autocorrelation in the observations,\n> > > though I cannot judge what that means in this concrete example. The\n> > > speedup is not that dramatic here, so SHA256 seems to be pretty\n> > > random.\n> > >\n> > > #include <stdio.h>\n> > > #include <string.h>\n> > > #include <stdint.h>\n> > > #include <openssl/evp.h>\n> > >\n> > > #ifdef POLYFILL\n> > > EVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in)\n> > > {\n> > >     EVP_MD_CTX *out = EVP_MD_CTX_new();\n> > >\n> > >     if (out != NULL && !EVP_MD_CTX_copy_ex(out, in)) {\n> > >         EVP_MD_CTX_free(out);\n> > >         out = NULL;\n> > >     }\n> > >     return out;\n> > > }\n> > > #endif\n> > >\n> > > #define REVERTED_BIT(n, position, width) (((n & (1 << position)) >>\n> > > position) << (width - position - 2))\n> > >\n> > > uint32_t revert_bits(uint32_t n, uint32_t width) {\n> > >     uint32_t result = 0;\n> > >     for (uint32_t i = 0; i < width; ++i) {\n> > >         result |= REVERTED_BIT(n, i, width);\n> > >     }\n> > >     return result;\n> > > }\n> > >\n> > > int main(int argc, const char **argv)\n> > > {\n> > >     const char needle[] = { 0xde, 0xad, 0xbe, 0xef };\n> > >     const EVP_MD *algo = EVP_sha256();\n> > >     EVP_MD_CTX *ctx = EVP_MD_CTX_new();\n> > >\n> > >     EVP_DigestInit_ex(ctx, algo, NULL);\n> > >     while (*++argv)\n> > >         EVP_DigestUpdate(ctx, *argv, strlen(*argv));\n> > >\n> > >     for (uint32_t n = 1; ; n++) {\n> > > #if (COUNTER_WIDTH != 0)\n> > >         uint32_t i = revert_bits(n, COUNTER_WIDTH);\n> > > #else\n> > >         uint32_t i = n;\n> > > #endif\n> > >         // printf(\"%u %u\\n\", n, i);\n> > >         char buf[16];\n> > >         char *p;\n> > >         unsigned char digest[32];\n> > >         EVP_MD_CTX *copy = EVP_MD_CTX_dup(ctx);\n> > >\n> > >         p = buf + sizeof(buf);\n> > >         for (uint32_t v = i; v; v /= 10)\n> > >             *--p = '0' + (v % 10);\n> > >         EVP_DigestUpdate(copy, p, buf + sizeof(buf) - p);\n> > >         EVP_DigestUpdate(copy, \"\\n\", 1);\n> > >         EVP_DigestFinal_ex(copy, digest, NULL);\n> > >         EVP_MD_CTX_free(copy);\n> > >         if (memmem(digest, sizeof(digest), needle, sizeof(needle)))\n> > >         {\n> > >             printf(\"counter width: %2u | n: %10u | i: %10u\\n\",\n> > > COUNTER_WIDTH, n, i);\n> > >             return 0;\n> > >         }\n> > >     }\n> > >     return 1;\n> > > }\n> > >\n> > > cc -DPOLYFILL -DCOUNTER_WIDTH=32 jk_evp.c -lssl -lcrypto -o jk_evp_msb_32\n> > > cc -DPOLYFILL -DCOUNTER_WIDTH=31 jk_evp.c -lssl -lcrypto -o jk_evp_msb_31\n> > > cc -DPOLYFILL -DCOUNTER_WIDTH=30 jk_evp.c -lssl -lcrypto -o jk_evp_msb_30\n> > > cc -DPOLYFILL -DCOUNTER_WIDTH=29 jk_evp.c -lssl -lcrypto -o jk_evp_msb_29\n> > > cc -DPOLYFILL -DCOUNTER_WIDTH=0 jk_evp.c -lssl -lcrypto -o jk_evp_0\n> > > counter width: 32 | n:  103832253 | i: 1588397616\n> > > counter width: 31 | n:   62413559 | i: 1003915120\n> > > counter width: 30 | n:  166340413 | i:  396135154\n> > > counter width: 29 | n:  137077701 | i:  171728193\n> > > counter width:  0 | n:  171728193 | i:  171728193\n> >\n> > I have to admit there is a bug in my previous code, it only works\n> > correctly for even numbers. It should have been:\n> >\n> > #define REVERTED_BIT(n, position, width) (((n & (1 << position)) >>\n> > position) << (width - position - 2 + (width & 1)))\n> >\n> > uint32_t revert_bits(uint32_t n, uint32_t width) {\n> >     uint32_t result = 0;\n> >     for (uint32_t i = 0; i < width; ++i) {\n> >         result |= REVERTED_BIT(n, i, width);\n> >     }\n> >     return result;\n> > }\n> >\n> > The actual performance measurements are:\n> > counter width: 32 | n:  103832253 | i: 1588397616\n> > counter width: 31 | n:  103832253 | i: 1588397616\n> > counter width: 30 | n:  166340413 | i:  396135154\n> > counter width: 29 | n:  166340413 | i:  396135154\n> > counter width: 28 | n:  268041599 | i: 2281045247 # 2**28 is close to\n> > the first finding when counting by incrementing the LSB, so this is\n> > slow.\n> > counter width: 27: This does not find anything, because 2**27 is lower\n> > than the first finding when counting by incrementing the LSB.\n> > counter width:  0 | n:  171728193 | i:  171728193 #\n> > math.log2(171728193) = 27.35555166834193\n>\n> As an interim solution, it could make sense to leave small input\n> unmodified, and to permute large texts to get rid of the natural\n> language manifold.\n"}]}