git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: SHA1 hash safety

From
TTkil <tkil@scrye.com>
Date
Apr 17, 2005, 04:43 UTC
Message-ID
<gacny8135.fsf@brand.scrye.com>
In-Reply-To
<20050416210934.11a27387.pj@sgi.com>
>>>>> "Tkil" == Tkil <tkil@scrye.com> writes:
Tkil> but the chance of any collision at all wigs me out.
>>>>> "Paul" == Paul Jackson <pj@sgi.com> writes:
Paul> Guess you're just going to get wigged out then.
Wig wig.  :)

I didn't mean "wigs me out to the point I won't use it" but more of "wigs me out so that I'm curious whether there are backup schemes worth considering".

In particular, the comparisons between hash collisions and hardware failure seem contrived -- if I have bad RAM, or a bad block on my HD, I can recover it from known good sources. But if the actual known good source is structured in such a way that a particular set of data cannot be represented, that bothers me.

In this case, the fact that it has to be the same length, same SHA-1, correct C, and functionally similar C at that, makes for a comforting cushion. Further, git wouldn't be the only representation; there would be periodic tarballs, different trees, etc.

On the other paw, if "effectively random" MS Word docs gave true MD5 collisions (when we have a proper MD5 hash computed over the entire document) in a "mere" 1e7 space, that is interesting/scary.

(I was also trying to add a few factoids to the MSW comment, as their structure could lead to collisions if (say) only the first 512 bytes were considered -- it's possible that nothing but size and date might change in that, and /those/ I can see colliding in 1e7 documents.)

Finally, I apologize for taking your time. I'm just watching this from the sidelines, and the questions above are just intellectual curiosity. :-/

(The only other thread I'm really following is people trying to chunk files in a way that would increase storage efficiency; reading the Venti paper, I was wondering how efficient it would be if a one-byte addition at the top of the file would generate all-new blocks, while the rsync-ish protocol seems to offer substantial relief. But if the "interesting history" fits in 10USD worth of HD, that might be enough. Babble.)

Thanks, t.

Previous: Paul JacksonNext: Paul Jackson
Message 29 of 30 in “SHA1 hash safety”
  1. David LangApr 16, 2005
  2. Ingo MolnarApr 16, 2005
  3. David LangApr 16, 2005
  4. Brian O'MahoneyApr 16, 2005
  5. C. Scott AnanianApr 16, 2005
  6. Petr BaudisApr 16, 2005
  7. C. Scott AnanianApr 16, 2005
  8. David LangApr 16, 2005
  9. Paul JacksonApr 16, 2005
  10. Martin MaresApr 16, 2005
  11. David A. WheelerApr 17, 2005
  12. Theodore Ts'oApr 18, 2005
  13. ross@lug.udel.eduApr 16, 2005
  14. Horst von BrandApr 17, 2005
  15. Brian O'MahoneyApr 18, 2005
  16. C. Scott AnanianApr 18, 2005
  17. Paul JacksonApr 16, 2005
  18. Brian O'MahoneyApr 16, 2005
  19. Andy IsaacsonApr 18, 2005
  20. C. Scott AnanianApr 18, 2005
  21. David MeybohmApr 19, 2005
  22. C. Scott AnanianApr 19, 2005
  23. David MeybohmApr 20, 2005
  24. David LangApr 16, 2005
  25. Paul JacksonApr 16, 2005
  26. David LangApr 16, 2005
  27. TkilApr 17, 2005
  28. Paul JacksonApr 17, 2005
  29. TkilApr 17, 2005
  30. Paul JacksonApr 17, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.