Re: SHA1 hash safety
- From
- Paul Jackson <pj@sgi.com>
- Date
- Apr 16, 2005, 19:16 UTC
- Message-ID
- <20050416121652.1b1a8645.pj@sgi.com>
- In-Reply-To
- <Pine.LNX.4.61.0504161040310.29343@cag.csail.mit.edu>
Scott wrote:
> Please, let's talk about hash collisions responsibly.
Agreed.
Chasing down links from the one Petr provided:
http://cryptography.hyperlink.cz/MD5_collisions.html
the best read I found was:
MD5 To Be Considered Harmful Someday http://eprint.iacr.org/2004/357.pdf
As the author, Dan Kaminsky, states:
> it is far too easy to overestimate the risks described in this paper.
This paper does a good job of explaining the vulnerabilities that MD5 has, currently (and yes, git uses SHA1 ...).
We have far greater vulnerabilities from intentional or accidental coding errors, inadequately audited code, root exploits of user (non-kernel) code, compilation and build tools, unreliable hardware (how many of us use non-ECC memory - I do), poorly administered systems, ...
--
I won't rest till it's the best ...
Programmer, Linux Scalability
Paul Jackson <pj@engr.sgi.com> 1.650.933.1373, 1.925.600.0401