git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [zooko@zooko.com: [Revctrl] colliding md5 hashes of human-meaningful

From
Llinux@horizon.com <linux@horizon.com>
Date
Jun 13, 2005, 21:01 UTC
Message-ID
<20050613210318.18965.qmail@science.horizon.com>
In-Reply-To
<Pine.LNX.4.58.0506131305550.8487@ppc970.osdl.org>
> No, I just am not letting paranoia mean that I sit around shivering all 
> day long.

I'm sorry if I implied that. I meant "paranoid" in the sense of "imagining attack"; you were saying there is no way to attack git via a collision attack on the underlying hash, and I objected.

I agree with you that:
- The attack is still wildly impractical, and
- Anything is better than the unauthenticated TCP we use these days!
>> The basic attack goes like this:
>> 
>> - I construct two .c files with identical hashes.
Show 8 quoted lines
> Ok, I have a better plan.
>
> - you learn to fly by flapping your arms fast enough
> - you then learn to pee burning gasoline
> - then, you fly around New York, setting everybody you see on fire, until 
>   people make you emperor.
>
> Sounds like a good plan, no?

ROFL! Oh my. That's worthy of reprinting. I was pleased with myself for making fun of the "what if there's an accidental hash collision" theory by assuming that kernel development would continue uninterrupted until the sun went nova, but this is truly masterful scorn.

> But perhaps slightly impractical.
There are just few laws of physics it violates.

Not to mention that New York is still a trifle touchy about the combination of flying and burning fossil fuels, and this poses problems for step 3.

> Now, let's go back to your plan. Why do you think your plan is any better 
> than mine?

I was trying to point out that a collision attack is possible. That is, *if* we assume that someone can has the ability to find a hash collision, *then* they can use that to break git's authenticity guarantees.

I wasn't addressing the plausibility of the "if" part. I agree that requiring the hashed text to be plausible C source makes all current attacks (including the MD5 ones) irrelevant, and reduces you to straight brute force, which is quite implausible.

But it *is* a collsion attack, not a preimage attack, and it *is* at least consistent with all known laws of physics.

I did *not* say, or mean to imply, that there was anything wrong with git's hashing.

Previous: Jason McMullanNext: Junio C Hamano
Message 4 of 6 in “Re: [zooko@zooko.com: [Revctrl] colliding md5 hashes of human-meaningful”
  1. linux@horizon.comJun 13, 2005
  2. Linus TorvaldsJun 13, 2005
  3. Jason McMullanJun 13, 2005
  4. linux@horizon.comJun 13, 2005
  5. Junio C HamanoJun 13, 2005
  6. Radoslaw SzkodzinskiJun 13, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.