# SHA-1 chosen-prefix colission attack

3 messages from 2020-01-07 to 2020-01-08. Participants: Kevin Daudt, Santiago Torres Arias, Jeff King.
Thread: https://gitlist.dev/t/52586

## Kevin Daudt, 2020-01-07 17:31

Subject: SHA-1 chosen-prefix colission attack
Message-ID: <20200107173111.GB923852@alpha>
URL: https://gitlist.dev/e/20200107173111.GB923852%40alpha

```
Researchers published new advances in creating collisions in SHA-1
hashes: https://sha-mbles.github.io/

> As a side result, this shows that it now costs less than 100k USD to
> break cryptography with a security level of 64 bits (i.e. to compute
> 264 operations of symmetric cryptography).

Kevin


```

## Santiago Torres Arias, 2020-01-07 20:31

Subject: Re: SHA-1 chosen-prefix colission attack
Message-ID: <20200107203147.r33c5plp5g7pmxmj@LykOS.localdomain>
URL: https://gitlist.dev/e/20200107203147.r33c5plp5g7pmxmj%40LykOS.localdomain
In-Reply-To: <20200107173111.GB923852@alpha>

```
> > As a side result, this shows that it now costs less than 100k USD to
> > break cryptography with a security level of 64 bits (i.e. to compute
> > 264 operations of symmetric cryptography).

Just to clarify:

    As a stopgap measure, the collision-detection library of Stevens and Shumow [SS17]
    can be used to detect attack attempts (it successfully detects our attack).

At the end of section 7.0,

Cheers
-Santiago

```

## Jeff King, 2020-01-08 07:30

Subject: Re: SHA-1 chosen-prefix colission attack
Message-ID: <20200108073042.GD1675456@coredump.intra.peff.net>
URL: https://gitlist.dev/e/20200108073042.GD1675456%40coredump.intra.peff.net
In-Reply-To: <20200107203147.r33c5plp5g7pmxmj@LykOS.localdomain>

```
On Tue, Jan 07, 2020 at 03:31:48PM -0500, Santiago Torres Arias wrote:

> > > As a side result, this shows that it now costs less than 100k USD to
> > > break cryptography with a security level of 64 bits (i.e. to compute
> > > 264 operations of symmetric cryptography).
> 
> Just to clarify:
> 
>     As a stopgap measure, the collision-detection library of Stevens and Shumow [SS17]
>     can be used to detect attack attempts (it successfully detects our attack).
> 
> At the end of section 7.0,

And if anyone is curious, you can test your build of Git against their
sample files by running:

  $ t/helper/test-tool sha1 <messageA
  fatal: SHA-1 appears to be part of a collision attack: 8ac60ba76f1999a1ab70223f225aefdc78d4ddc0

Unfortunately you can't test with actual Git objects, because their
chosen-prefixes don't have object headers. They do estimate that a
classical collision is down to ~11k USD to compute, so maybe we'll see
one eventually. :)

-Peff

```
