git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [zooko@zooko.com: [Revctrl] colliding md5 hashes of human-meaningful documents]

From
MUMartin Uecker <muecker@gmx.de>
Date
Jun 12, 2005, 14:53 UTC
Message-ID
<20050612145342.GA9882@macavity>
In-Reply-To
<20050612082555.GB6620@pasky.ji.cz>
On Sun, Jun 12, 2005 at 10:25:55AM +0200, Petr Baudis wrote:
Show 17 quoted lines
> ----- Forwarded message from zooko@zooko.com -----
> 
> There is nothing theoretically surprising about this, but hopefully its
> concreteness and the accompanying scenario will make an impression on people
> on people.  The same technique should work to generate two documents with
> identical SHA1 hashes.
> 
> http://www.cits.rub.de/MD5Collisions/
> 
> ----- End forwarded message -----
> 
> I expected the two postscript files differing in some huge binary blob,
> but it turns out the binary part is very small (about 256 bytes) and
> only few (about nine) bytes are different, contrary to how people have
> predicted the collisions. This is much more close to finding a collision
> between similar pure C files, I think. Rather unsettling.
> 

This attack scenario doesn't demonstrate the danger of hash collisions but the danger of signing documents you do not understand. The same technique works exactly in the same way with postscript files which are actually identical but produce different output under different conditions (time, fonts installed on the printer whatever).

Never sign anything but plain text or documents which are created in a controlled way and avoid signing documents you did not create yourself.

Martin
-- 
One night, when little Giana from Milano was fast asleep,
she had a strange dream.
Previous: Morten WelinderNext: Linus Torvalds
Message 3 of 5 in “[zooko@zooko.com: [Revctrl] colliding md5 hashes of human-meaningful documents]”
  1. Petr BaudisJun 12, 2005
  2. Morten WelinderJun 12, 2005
  3. Martin UeckerJun 12, 2005
  4. Linus TorvaldsJun 12, 2005
  5. Daniel BarkalowJun 14, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.