git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: SHA1 hash safety

From
Rross@lug.udel.edu <ross@lug.udel.edu>
Date
Apr 16, 2005, 15:49 UTC
Message-ID
<20050416154951.GB13373@jose.lug.udel.edu>
In-Reply-To
<Pine.LNX.4.61.0504161040310.29343@cag.csail.mit.edu>
On Sat, Apr 16, 2005 at 10:58:15AM -0400, C. Scott Ananian wrote:
Show 5 quoted lines
> Even given the known weaknesses in MD5, it would take much more than a 
> million documents to find MD5 collisions.  I can only conclude that the 
> hash was being used incorrectly; most likely truncated (my wild-ass guess 
> would be to 32 bits; a collision is likely with > 50% probability in a 
> million document store for a hash of less than 40 bits).

I've also seen non thread-safe GUID generation, using MD5m hit collisions: but of course that was due to the fact that the code had thread safety issues, not because anyone actually ever hit a MD5 collision...

Of course there are constructed cases of MD5 collision, but those are pretty disinteresting. Give me two files that have useful content and the same hash, and then I'll be impressed.

Linus has already weighed in that he doesn't give a crap. All the crypto-babble about collision whitepapers is uninteresting without a repo that has real collisions. git is far too cool as is - prove I should be concerned.

-- 
Ross Vandegrift
ross@lug.udel.edu

"The good Christian should beware of mathematicians, and all those who
make empty prophecies. The danger already exists that the mathematicians
have made a covenant with the devil to darken the spirit and to confine
man in the bonds of Hell."
	--St. Augustine, De Genesi ad Litteram, Book II, xviii, 37
Previous: Theodore Ts'oNext: Horst von Brand
Message 13 of 30 in “SHA1 hash safety”
  1. David LangApr 16, 2005
  2. Ingo MolnarApr 16, 2005
  3. David LangApr 16, 2005
  4. Brian O'MahoneyApr 16, 2005
  5. C. Scott AnanianApr 16, 2005
  6. Petr BaudisApr 16, 2005
  7. C. Scott AnanianApr 16, 2005
  8. David LangApr 16, 2005
  9. Paul JacksonApr 16, 2005
  10. Martin MaresApr 16, 2005
  11. David A. WheelerApr 17, 2005
  12. Theodore Ts'oApr 18, 2005
  13. ross@lug.udel.eduApr 16, 2005
  14. Horst von BrandApr 17, 2005
  15. Brian O'MahoneyApr 18, 2005
  16. C. Scott AnanianApr 18, 2005
  17. Paul JacksonApr 16, 2005
  18. Brian O'MahoneyApr 16, 2005
  19. Andy IsaacsonApr 18, 2005
  20. C. Scott AnanianApr 18, 2005
  21. David MeybohmApr 19, 2005
  22. C. Scott AnanianApr 19, 2005
  23. David MeybohmApr 20, 2005
  24. David LangApr 16, 2005
  25. Paul JacksonApr 16, 2005
  26. David LangApr 16, 2005
  27. TkilApr 17, 2005
  28. Paul JacksonApr 17, 2005
  29. TkilApr 17, 2005
  30. Paul JacksonApr 17, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.