Re: Now that SHA-1 is cracked...

thurberk_at_cscsw.com
Date: 02/22/05


Date: 22 Feb 2005 06:59:44 -0800

Matt Gibson wrote:
<snip A and B>
> C) Say the paper is right, and they can now break SHA-1 in ~2^53
attempts.
> What does this mean to most people? Nothing. With these attacks,
you
> cannot just get "I will give you 1 million dollars" to "I will give
you 10
> million dollars". You'd have a better chance of getting
"09sdfkj3uih3wi8"
> to hash to the same value.

Certainly true--this alleged vulnerability has no measurable effect on
signed messages. However and unfortunately, some applications use
SHA-1 as a more basic building block of their security. The most
common example, of course, is storing the hash of a password in an
accessible xml file, and authenticating the user if a hash of his input
matches the hash in the xml file. Assuming that the Chinese can do
everything they claim, and that the padding problem can likewise be
overcome, these collisions surely reduce the security of such
applications by the advertised amount.



Relevant Pages

  • Re: Now that SHA-1 is cracked...
    ... > to hash to the same value. ... However and unfortunately, some applications use ... SHA-1 as a more basic building block of their security. ... matches the hash in the xml file. ...
    (microsoft.public.inetserver.iis)
  • Re: Now that SHA-1 is cracked...
    ... > to hash to the same value. ... However and unfortunately, some applications use ... SHA-1 as a more basic building block of their security. ... matches the hash in the xml file. ...
    (microsoft.public.windows.server.security)
  • Re: Now that SHA-1 is cracked...
    ... > to hash to the same value. ... However and unfortunately, some applications use ... SHA-1 as a more basic building block of their security. ... matches the hash in the xml file. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Now that SHA-1 is cracked...
    ... > to hash to the same value. ... However and unfortunately, some applications use ... SHA-1 as a more basic building block of their security. ... matches the hash in the xml file. ...
    (microsoft.public.exchange2000.connectivity)
  • Re: Password hashes
    ... There are only LM and NTLM hashes. ... There is an NTLMv2 hash but it is not stored. ... authenticating to the network. ... Auditing and reviewing the security logs ...
    (microsoft.public.windowsxp.security_admin)