git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Re: SHA1 hash safety

From
C. Scott Ananian <cscott@cscott.net>
Date
Apr 16, 2005, 15:36 UTC
Message-ID
<Pine.LNX.4.61.0504161114530.29343@cag.csail.mit.edu>
In-Reply-To
<20050416151116.GC19099@pasky.ji.cz>
On Sat, 16 Apr 2005, Petr Baudis wrote:
>> I know the current state of the art here.  It's going to take more than
>> just hearsay to convince me that full 128-bit MD5 collisions are likely.
>
> http://cryptography.hyperlink.cz/MD5_collisions.html
OK, OK, I spoke too sloppily.  Let me rephrase:
   It's going to take more than just hearsay to convince me that full
   128-bit MD5 collisions *IN ARBITRARILY CHOSEN DOCUMENTS* are likely.
I could add, "WITHOUT SPECIAL EFFORT BY AN ATTACKER".

But you're right, I was too busy thrashing around with the basic probability cluestick to carefully distinguish MD5 (in which *collisions* can be found fairly easily now by an attacker, although not *preimages*) and SHA1 (which is what git is actually using, and still requires 2^69 hash computations to collide).

And note again that these are not preimage attacks. Even with MD5, an attacker can't arbitrarily change existing code in the Linux kernel by creating a malicious file with the same MD5 hash.

But extreme caution is necessary, because both of these hash mechanisms have been shown to be weak, and algorithms grow weaker with time, not stronger.

I think the only conclusion that can be made is that "one should not rely 
on the hash for security".  And I don't believe that we are.  We should be
careful to continue saying "branch 46f<mumble> *in Linus' tree*" instead 
of just "branch 46f<mumble>" and assuming that that is unique.  The 
security is provided by Linus' control over his repository, not by the 
hash.
   --scott

[The 'MD5 collisions in 15 minutes on a laptop' paper did surprise me. I vaguely remember hearing about this before, but I'd forgotten just how broken MD5 is. It's still a fine *hash* function; just not a terribly good *cryptographically secure* hash function.]

Israel PBSUCCESS $400 million in gold bullion President Nader jihad 
RNC LPMEDLEY agent HTKEEPER Cheney SEQUIN SARANAC Clinton biowarfare
                          ( http://cscott.net/ )
Previous: Petr BaudisNext: David Lang
Message 7 of 30 in “SHA1 hash safety”
  1. David LangApr 16, 2005
  2. Ingo MolnarApr 16, 2005
  3. David LangApr 16, 2005
  4. Brian O'MahoneyApr 16, 2005
  5. C. Scott AnanianApr 16, 2005
  6. Petr BaudisApr 16, 2005
  7. C. Scott AnanianApr 16, 2005
  8. David LangApr 16, 2005
  9. Paul JacksonApr 16, 2005
  10. Martin MaresApr 16, 2005
  11. David A. WheelerApr 17, 2005
  12. Theodore Ts'oApr 18, 2005
  13. ross@lug.udel.eduApr 16, 2005
  14. Horst von BrandApr 17, 2005
  15. Brian O'MahoneyApr 18, 2005
  16. C. Scott AnanianApr 18, 2005
  17. Paul JacksonApr 16, 2005
  18. Brian O'MahoneyApr 16, 2005
  19. Andy IsaacsonApr 18, 2005
  20. C. Scott AnanianApr 18, 2005
  21. David MeybohmApr 19, 2005
  22. C. Scott AnanianApr 19, 2005
  23. David MeybohmApr 20, 2005
  24. David LangApr 16, 2005
  25. Paul JacksonApr 16, 2005
  26. David LangApr 16, 2005
  27. TkilApr 17, 2005
  28. Paul JacksonApr 17, 2005
  29. TkilApr 17, 2005
  30. Paul JacksonApr 17, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.