git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Exploiting SHA1's "XOR weakness" allows for faster hash calculation

From
MKMarko Kreen <markokr@gmail.com>
Date
Dec 5, 2012, 12:26 UTC
Message-ID
<CACMqXC+jfkvj_ot0x6La6gOHypuXE-LX41V04_yQdZ+gytSDDw@mail.gmail.com>
In-Reply-To
<k9n3jd$akg$1@ger.gmane.org>

On Wed, Dec 5, 2012 at 11:19 AM, Sebastian Schuberth <sschuberth@gmail.com> wrote:

Show 6 quoted lines
> to say it in advance: I do not want to trigger any bogus security discussion
> here. Instead, I believe the findings from [1] allow for an up to 20% faster
> SHA1 calculation, if my brief reading of the presentation is correct. Any
> opinions on integration this optimization into Git?
>
> [1] https://hashcat.net/p12/js-sha1exp_169.pdf

Pretty cool find. Although it's not actual cryptographic weakness, it does show some gaps in designers thinking - as there are simple optimizations available to crackers but not users.

It does seem unusable for real implementation - the 20% win is available only after the data is processed properly once. Then after changing the data a little, you can calculate next hash faster.

There still small possibility that there is way to optimize W calculation for the first run, but it does seem really hard, and even impossible while trying to keep the cache usage small.

-- 
marko
Previous: Sebastian SchuberthNext: Theodore Ts'o
Message 2 of 4 in “Exploiting SHA1's "XOR weakness" allows for faster hash calculation”
  1. Sebastian SchuberthDec 5, 2012
  2. Marko KreenDec 5, 2012
  3. Theodore Ts'oDec 5, 2012
  4. Sebastian SchuberthDec 6, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.