Re: SHA-1 distributed collision search



On Aug 29, 4:13 am, Francois Grieu <fgr...@xxxxxxxxx> wrote:
-----BEGIN PGP SIGNED MESSAGE-----

there reportedly is an ongoing distributed computing effort
aimed at finding a SHA-1 collision,

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3


am curious about your pgp key,

it appears to have been generated recently (11/july/2007),
and is an unusual size (1984) to choose for current key use,
(even for pgp 2.x)

the signature verifies,
and it might be a good idea to cut down on the spamming here,
if people used pgp signing with a key they generated just for this
group,

but if you wanted to do that, 1024 would be just as good,
and if not, 2048 would take only slightly longer to generate


caveats:

-signature should be verified from the 'original' post, not the html
newsreader view,

-avoid any e-mail addresses in the plaintext, as these are sometimes
deleted/altered by some newsreaders/posters (e.g. google)

- don't use dashes, like in the front of this line ;-)
pgp clearsigning will change the line by putting a '-' and blank space
in front of the beginning dash
(it will still verify, but might make it annoying if someone were
posting a public key,
or pgp message as part of the cleartext)


vedaal

.



Relevant Pages

  • Re: OT cant read posting.
    ... > contains the message and the .asc file contains a PGP signature. ... The structure of his postings is incompatible with your newsreader. ... Prior to the prolog is the information about his message being openpgp ...
    (comp.security.misc)
  • Re: Delphi Blogsphere
    ... > I've seen newsgroup posts signed using PGP. ... until somebody writes a newsreader with digital signing ...
    (borland.public.delphi.non-technical)
  • Re: SHA-1 distributed collision search
    ... aimed at finding a SHA-1 collision, ... am curious about your pgp key, ... that I have recently been impersonated on sci.crypt; with moderate ... thinking or expertise it was easy to distinguish the forgeries ...
    (sci.crypt)