git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Revctrl] colliding md5 hashes of human-meaningful

From
RSRadoslaw Szkodzinski <astralstorm@gorzow.mm.pl>
Date
Jun 13, 2005, 20:52 UTC
Message-ID
<42ADF1F2.1070008@gorzow.mm.pl>
In-Reply-To
<20050613195038.9191.qmail@science.horizon.com>
linux@horizon.com wrote:
Show 22 quoted lines
>>So the problem is totally different from the way git uses a hash. In the 
>>git model, an attacker by definition cannot control both versions of a 
>>file, since if he controls just _one_ version, he doesn't need to do the 
>>attack in the first place!
>>    
>>
>
>You are insufficiently paranoid, Grasshopper.
>
>The basic attack goes like this:
>
>- I construct two .c files with identical hashes.  One is something
>  useful; perhaps a device driver for some piece of hardware that my
>  desired target has.  The other is similar, but includes a remote
>  root explot.
>
>  (With an n-bit hash and an automated way to make harmless changes
>  to source files, I can generate 2^(n/2) variants of each and expect to
>  get a match, even in the absence of a better attack.)
>
>  
>
And you get lots of nonsense in the new file.
Show 5 quoted lines
>- I submit the first one to the Linux kernel.  It's valid and gets
>  merged.
>
>  
>

And funny as it is, when the hole is found you're busted. Or at least the first person responsible. You probably couldn't shadow yourself enough not to get caught.

Show 5 quoted lines
>- A kernel release, including the "interesting" driver, gets made and
>  sprinkled with holy penguin pee.  Signatures, hashes, and all that.
>
>  
>
Which mean that you can't change your name on the project. See above.
Show 6 quoted lines
>- Through various means (possibly just running a kernel download mirror,
>  or possibly by splicing into my target's upstream Internet connection),
>  I substitute the malware file for the real source code.
>
>  
>

If you can splice into the connection, you can put there anything you want, including another kernel and any amount of exploits. Even with SSH. Ever heard of man-in-the-middle attacks?

With high-grade security you won't be able to splice into the connection, as it'll be fully encrypted (with HTH key exchange) and/or randomised using things like EFF's Tor. Then they can check with kernel.org or any other mirror.

>- My target verifies all the hashes and signatures, decides that this "Linus"
>  person signing it is trustworthy, and compiles and installs the kernel.
>  
>

And they're so unforseeing that they don't check the sources of the drivers they use. Funny. And if they don't use it, you'll have a problem with enabling your exploit. Your best target would be a scheduler, but that's heavily scrutinised.

>- I walk in my back door and do suitable rude things.
>
>  
>
Like going to jail.
Show 5 quoted lines
>The point is, it *is* possible for an attacker to control both versions of
>a file.  The reason he needs to do the attack is that one version looks
>legitimate and the other includes a Nasty Surprise.
>  
>
It is in theory. Tell someone when you mount such an attack on anybody.
AstralStorm
Previous: Junio C Hamano
Message 6 of 6 in “Re: [zooko@zooko.com: [Revctrl] colliding md5 hashes of human-meaningful”
  1. linux@horizon.comJun 13, 2005
  2. Linus TorvaldsJun 13, 2005
  3. Jason McMullanJun 13, 2005
  4. linux@horizon.comJun 13, 2005
  5. Junio C HamanoJun 13, 2005
  6. Radoslaw SzkodzinskiJun 13, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.