git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: SHA1 hash safety

From
C. Scott Ananian <cscott@cscott.net>
Date
Apr 16, 2005, 14:58 UTC
Message-ID
<Pine.LNX.4.61.0504161040310.29343@cag.csail.mit.edu>
In-Reply-To
<4261132A.3090907@khandalf.com>
On Sat, 16 Apr 2005, Brian O'Mahoney wrote:
> (1) I _have_ seen real-life collisions with MD5, in the context of
>    Document management systems containing ~10^6 ms-WORD documents.

Dude! You could have been *famous*! Why the aitch-ee-double-hockey-sticks didn't you publish this when you found it? Seriously, man.

Even given the known weaknesses in MD5, it would take much more than a million documents to find MD5 collisions. I can only conclude that the hash was being used incorrectly; most likely truncated (my wild-ass guess would be to 32 bits; a collision is likely with > 50% probability in a million document store for a hash of less than 40 bits).

I know the current state of the art here. It's going to take more than just hearsay to convince me that full 128-bit MD5 collisions are likely. I believe there are only two or so known to exist so far, and those were found by a research team in China (which, yes, is fairly famous among the cryptographic community now after publishing a paper consisting of little apart from the two collisions themselves).

Please, let's talk about hash collisions responsibly.  I posted earlier 
about the *actual computed probability* of finding two files with an SHA-1 
collision before the sun goes supernova.  It's 10^28 to 1 against.
The recent cryptographic works has shown that there are certain situations 
where a decent amount of computer work (2^69 operations) can produce two 
sequences with the same hash, but these sequences are not freely chosen; 
they've got very specific structure.  This attack does not apply to 
(effectively) random files sitting in a SCM.
   http://www.schneier.com/blog/archives/2005/02/sha1_broken.html

That said, Linux's widespread use means that it may not be unimaginable for an attacker to devote this amount of resources to an attack, which would probably involve first committing some specially structured file to the SCM (but would Linus accept it?) and then silently corrupting said file via a SHA1 collision to toggle some bits (which would presumably Do Evil). Thus hashes other than SHA1 really ought to be considered...

...but the cryptographic community has not yet come to a conclusion on what the replacement ought to be. These attacks are so new that we don't really understand what it is about the structure of SHA1 which makes them possible, which makes it hard to determine which other hashes are similarly vulnerable. It will take time.

I believe Linus has already stated on this list that his plan is to 
eventually provide a tool for bulk migration of an existing SHA1 git 
repository to a new hash type.   Basically munging through the repository 
in bulk, replacing all the hashes.  This seems a perfectly adequate 
strategy at the moment.
  --scott
WASHTUB Panama Minister Moscow explosives KUGOWN hack Marxist LPMEDLEY 
genetic immediate radar SCRANTON COBRA JANE KGB Shoal Bay atomic Bejing
                          ( http://cscott.net/ )
Previous: Brian O'MahoneyNext: Petr Baudis
Message 5 of 30 in “SHA1 hash safety”
  1. David LangApr 16, 2005
  2. Ingo MolnarApr 16, 2005
  3. David LangApr 16, 2005
  4. Brian O'MahoneyApr 16, 2005
  5. C. Scott AnanianApr 16, 2005
  6. Petr BaudisApr 16, 2005
  7. C. Scott AnanianApr 16, 2005
  8. David LangApr 16, 2005
  9. Paul JacksonApr 16, 2005
  10. Martin MaresApr 16, 2005
  11. David A. WheelerApr 17, 2005
  12. Theodore Ts'oApr 18, 2005
  13. ross@lug.udel.eduApr 16, 2005
  14. Horst von BrandApr 17, 2005
  15. Brian O'MahoneyApr 18, 2005
  16. C. Scott AnanianApr 18, 2005
  17. Paul JacksonApr 16, 2005
  18. Brian O'MahoneyApr 16, 2005
  19. Andy IsaacsonApr 18, 2005
  20. C. Scott AnanianApr 18, 2005
  21. David MeybohmApr 19, 2005
  22. C. Scott AnanianApr 19, 2005
  23. David MeybohmApr 20, 2005
  24. David LangApr 16, 2005
  25. Paul JacksonApr 16, 2005
  26. David LangApr 16, 2005
  27. TkilApr 17, 2005
  28. Paul JacksonApr 17, 2005
  29. TkilApr 17, 2005
  30. Paul JacksonApr 17, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.