git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Exploiting SHA1's "XOR weakness" allows for faster hash calculation

From
Sebastian Schuberth <sschuberth@gmail.com>
Date
Dec 6, 2012, 08:11 UTC
Message-ID
<CAHGBnuN1AwjAFeJMizXu9e-iD3n1GuWMNm9OPxCH7t1BcGz8Rw@mail.gmail.com>
In-Reply-To
<20121205172011.GH18885@thunk.org>
On Wed, Dec 5, 2012 at 6:20 PM, Theodore Ts'o <tytso@mit.edu> wrote:
Show 8 quoted lines
> It's only useful if you are trying to do brute-force password
> cracking, where the password is being hashed in a very specific way.
> (If for example the password was replicated N times in the input
> buffer for SHA-1, instead of keeping the padding constant in the rest
> of theinput buffer, this particular optimization would't apply.)
>
> In any case, it's not at all applicable for general purpose checksum
> calculations, and hence wouldn't apply to git.
Thanks for the explanation.
-- 
Sebastian Schuberth
Previous: Theodore Ts'o
Message 4 of 4 in “Exploiting SHA1's "XOR weakness" allows for faster hash calculation”
  1. Sebastian SchuberthDec 5, 2012
  2. Marko KreenDec 5, 2012
  3. Theodore Ts'oDec 5, 2012
  4. Sebastian SchuberthDec 6, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.