Unix Technical Forum

Re: Question related to the Hash-Algorithms used for the Ports

This is a discussion on Re: Question related to the Hash-Algorithms used for the Ports within the mailing.openbsd.tech forums, part of the OpenBSD category; --> Marc Bevand wrote: > | Finding a collision for both MD5 and SHA-1 at the same time is > ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 08:49 AM
Dries Schellekens
 
Posts: n/a
Default Re: Question related to the Hash-Algorithms used for the Ports

Marc Bevand wrote:

> | Finding a collision for both MD5 and SHA-1 at the same time is
> | completely improbable.
>
> Finding a collision for SHA-1 was also deemed completely improbable ten
> years ago. However nowadays the attack seems very probable.
>
> My point is, finding a collision for both MD5 and SHA-1 will eventually
> get accomplished some day. If it was really considered improbable, then
> I suggest cryptographers stop researching secure hashing algorithms and
> start using the hash function H(x) = MD5(x) . SHA1(x), where '.' is the
> concatenation operator.


The performance of this hash function will be poor.

All this is irrelevant for the application we are looking at, namely
OpenBSD ports. As kjell pointed out, you need to perform a second
preimage attack and not a collision attack. Please read
http://www.ecrypt.eu.org/documents/S...H_STMT-1.1.pdf to
clearly understand the difference.

All the attacks that have been found so far are collision attacks, not
second preimage attacks. Therefore, these attacks mainly have
implications on digital signatures.

If an attacker succeeds in finding a second preimage for a certain hash
value (of a tarball you want to download), he will also need to
construct a corrupted compressed tarball with the second preimage. Not
so simple either.


Cheers,

Dries

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 09:36 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com