Re: md5 collision



matt_left_coast wrote:

> Unruh wrote:
>
>>>When dealing with the first case, you create the first of the two files,
>>>then the file IS known. Then you would be dealing with the second case.
>>
>> But you have to create them together. You cannot create one and then make
>> another which has the same md5.
>
> Exact process, please.

The logic here escapes me. Unruh appears to be claiming that
you cannot do something ("cannot create one and then make
another which has the same md5"), and matt_left_coast appears
to be asserting that Unruh should support that claim by
detailing how to do something. You cannot show that something
is impossible by showing how to do something. If
matt_left_coast wishes to claim that one can find a preimage
to a given hash, it's up to him to specify how.

A recent paper on md5 attacks is "Improved Collision Attack on MD5"
by Yu Sasaki, Yusuke Naito, Noboru Kunihiro, and Kazuo Ohta,
available at http://eprint.iacr.org/2005/400.pdf. The procedure
is outlined in section 3.4. While the details are not essential
to this discussion, the alert reader will note that the attack
does *not* produce a preimage for a given hash, but rather produces
a pair of messages whose hashes match. Unruh is quite right.

--
Peter Pearson
To get my email address, substitute:
nowhere -> spamcop, invalid -> net

.



Relevant Pages

  • Re: md5 collision
    ... Unruh wrote: ... > beforehand. ... Then you would be dealing with the second case. ... creation of the first file. ...
    (comp.os.linux.security)
  • Re: md5 collision
    ... >Unruh wrote: ... Then you would be dealing with the second case. ... Go read the papers. ... Prev by Date: ...
    (comp.os.linux.security)
  • Re: md5 collision
    ... Unruh wrote: ... Then you would be dealing with the second case. ... Exact process, please. ... Prev by Date: ...
    (comp.os.linux.security)
  • Re: md5 collision
    ... Unruh wrote: ... Then you would be dealing with the second case. ... Exact process please. ... Prev by Date: ...
    (comp.os.linux.security)
  • Re: RedHat Linux 7.3 Question
    ... Hash: SHA1 ... Unruh wrote: ... The problem is that the security updates have never been applied and do not ...
    (comp.os.linux.setup)