git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [zooko@zooko.com: [Revctrl] colliding md5 hashes of human-meaningful documents]

From
Daniel Barkalow <barkalow@iabervon.org>
Date
Jun 14, 2005, 02:06 UTC
Message-ID
<Pine.LNX.4.21.0506132141250.30848-100000@iabervon.org>
In-Reply-To
<Pine.LNX.4.58.0506120949150.2286@ppc970.osdl.org>
On Sun, 12 Jun 2005, Linus Torvalds wrote:
> Put another way: you could use this exact example for a version of git
> that uses md5-sums instead of sha1's, but it wouldn't show anything at all 
> about a git vulnerability even so.

You couldn't use this exact example for an md5 git; git compresses the files before hashing, which means that you don't have an md5 block of arbitrary data you can replace with a different arbitrary block because it wouldn't decompress.

Of course, if zlib has a way of saying, "if bytes 256-511 match 512-767, decompress the first of the two records starting at 768, otherwise decompress the second" then the attack would work, and we should all by worried (and disturbed by zlib in general). Chances are that it would be impractical to find a pair of blocks such that they are both valid in the same part of a zlib record and both leave the compression context such that the same remaining content decompresses successfully and both have the same md5 hash, let alone getting the results in both cases to be valid C that depends on the difference between the blocks. It's possible that you could get it to work with only a moderately large number of weak collisions between very similar blocks, but it's not nearly so easy a task.

	-Daniel
*This .sig left intentionally blank*
Previous: Linus Torvalds
Message 5 of 5 in “[zooko@zooko.com: [Revctrl] colliding md5 hashes of human-meaningful documents]”
  1. Petr BaudisJun 12, 2005
  2. Morten WelinderJun 12, 2005
  3. Martin UeckerJun 12, 2005
  4. Linus TorvaldsJun 12, 2005
  5. Daniel BarkalowJun 14, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.