git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC] adding support for md5

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Aug 18, 2006, 11:37 UTC
Message-ID
<Pine.LNX.4.63.0608181330210.28360@wbgn013.biozentrum.uni-wuerzburg.de>
In-Reply-To
<44E5A416.9040709@sinister.cz>
Hi,
On Fri, 18 Aug 2006, Trekie wrote:
Show 9 quoted lines
> Johannes Schindelin wrote:
> > SHA1 has been broken (collisions have been found):
> > 
> > http://www.schneier.com/blog/archives/2005/02/sha1_broken.html
> 
> I don't think you're right. That blog just says, that Wang can find
> 
> "collisions in the the full SHA-1 in 2**69 hash operations, much less
> than the brute-force attack of 2**80 operations based on the hash length."
True. I have not heard of a collision either.
> The point is why use MD5 if anyone can compute a collision?

It does not suffice to generate collisions to make a hash unusable for our purposes: you would have to find a way to produce another text for a _given_ hash. Plus, this text would not only have to look meaningful, but compile. And preferrably introduce a back door.

Granted, once people find out how to generate another text, they can try to "optimize" some block between "/*" and "*/", so that the hash stays the same. But AFAICT none of the breaks of SHA1 or MD5 point into such a direction. Yet.

But _even if_ somebody succeeds in all that, that somebody has to convince _you_ to pull. And if you already have that object (the "good" version), it will not get overwritten.

Ciao, Dscho

Previous: TrekieNext: Jon Smirl
Message 9 of 20 in “[RFC] adding support for md5”
  1. David RientjesAug 18, 2006
  2. Nguyễn Thái Ngọc DuyAug 18, 2006
  3. Johannes SchindelinAug 18, 2006
  4. Petr BaudisAug 18, 2006
  5. David RientjesAug 18, 2006
  6. TrekieAug 18, 2006
  7. Johannes SchindelinAug 18, 2006
  8. TrekieAug 18, 2006
  9. Johannes SchindelinAug 18, 2006
  10. Jon SmirlAug 18, 2006
  11. Johannes SchindelinAug 19, 2006
  12. Linus TorvaldsAug 19, 2006
  13. Chris WedgwoodAug 21, 2006
  14. Junio C HamanoAug 22, 2006
  15. Shawn PearceAug 23, 2006
  16. Junio C HamanoAug 23, 2006
  17. Shawn PearceAug 23, 2006
  18. Junio C HamanoAug 24, 2006
  19. Shawn PearceAug 24, 2006
  20. Junio C HamanoAug 24, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.