Live data from Hacker News

We broke 92% of SHA-256 – you should start to migrate from it

stateofutopia.com

51–60 of 86 posts

Re: We broke 92% of SHA-256 – you should start to migrate from it

#51

I know people (especially around here) hate it when people just post AI output, and I generally agree, since it is trivial for anyone else who is interested to do the same thing. However, the majority of the comments here are from people seemingly asking the author (or someone else) to explain how significant this is, without having taken that step themselves. So while I normally wouldn't do this, in this case it see…

Extraordinary claims require extraordinary evidence, and the burden of proof lies with the one making the claim.

See also https://en.wikipedia.org/wiki/Brandolini%27s_law -

> The amount of energy needed to refute bullshit is an order of magnitude bigger than that needed to produce it.

Re: We broke 92% of SHA-256 – you should start to migrate from it

#52
post #42

Earlier quoted context omitted.

[flagged]

If you can't tell the difference between MD5 and SHA-256, you should not be making claims such as the one in the title.

edited to clarify, thanks for pointing it out. It wouldn't be responsible for us to only publish when we got to the same stage for SHA-256, since at that point TLS and other certificates would be considered compromised.

Re: We broke 92% of SHA-256 – you should start to migrate from it

#53

Earlier quoted context omitted.

Is a partial collision an indicator that it could be broken? The "we broke it" seems an exageration, but maybe that's a failure of my understanding.

Possible. It's up to people to decide if they're OK with a known 92% collision out there (with the unknown being there could be a 100%), or go for something stronger.

Thanks, you have this exactly right. The unknown part is especially worrying because we didn't implement many of the strongest ways to make to the final stretch yet, i.e. Wang-style message modification. Our result is basically a very strong direction in this cryptographic research, but not a full break yet.

Re: We broke 92% of SHA-256 – you should start to migrate from it

#54

Are you sure you asked enough times for money on the website? I only counted 5 instances, not counting the AI-produced PDF doc.

I didn't ask for money on the website.

That's a direct lie, just read the page you ostensibly wrote. It contains several times the imperative "support us" and talk about paying your bills, which is obviously asking for money.

You know what, fuck this. It's Friday night and I'm talking to a very low capability bot, this is bullshit.

Hacker News needs to do better than allowing this trash to the front page, else I'm just done.

Re: We broke 92% of SHA-256 – you should start to migrate from it

#56

Earlier quoted context omitted.

I didn't ask for money on the website.

That's a direct lie, just read the page you ostensibly wrote. It contains several times the imperative "support us" and talk about paying your bills, which is obviously asking for money. You know what, fuck this. It's Friday night and I'm talking to a very low capability bot, this is bullshit. Hacker News needs to do better than allowing this trash to the front page, else I'm just done.

Thanks, I didn't realize I'd made it to the front page. I'll make it clearer that you are not paying us any money if you choose to visit our sponsor.

Re: We broke 92% of SHA-256 – you should start to migrate from it

#57

For a shorter executive summary, what does "broke" mean here? Can you reliably produce collisions now for 92% of SHA-256 digests?

No, or we would have said so. It means that by relaxing the equations schedule somewhat, we are able to find a pair of differing messages that produce the same digest. However, we only relax the schedule a little bit, we still enforce 59 out of 64 schedule equations through the full 64 rounds - which is why we're only 92% of the way through to breaking it and not 100% of the way as we are with MD5. Importantly, we are not yet implementing the most advanced technique of Wang-style message modification, and we therefore expect that someone will be able to satisfy all 64 equations soon. This could result in an actual full-schedule, full-round collision. The previous record was only just 39 rounds out of 64 rounds, leaving 25 rounds, usually each of which mixes the message up completely. As mentioned in the paper, this attacks the problem from a different direction.

Re: We broke 92% of SHA-256 – you should start to migrate from it

#58
post #19

> it is possible that we'll find relations that carry across the entire double-SHA-256 pipeline Bitcoin mining is a partial second preimage of 0x00 though, not a collision, that statement just seems to be so outside the realm of what they’re claiming to have done. Even MD5, the most widely known to be broken hash, would be secure when used in the same way bitcoin uses SHA256 (other than being too short now, bitcoin m…

Thanks, you're right. My "it is possible" is doing some heavy lifting there :). We've found theorems (stated in the paper) that carry through 64 rounds, so it is possible that theorems might carry through the full 128 rounds of double-SHA256. Bitcoin's proof-of-work is indeed a "partial second preimage", and constraints a certain number of leading zeros, i.e. a certain number of set bits. It's possible (there we go again) that this could leave enough wiggle room for large algabraic solvers like kissat to satisfy a large number of clauses about them. So far nobody is doing that, and ASICs are very simplistic. However, we are not making any claims about preimage attacks in this paper!

Re: We broke 92% of SHA-256 – you should start to migrate from it

#59
post #13

The "Intermediate Report" [1] lists the authors as "Robert V. and Claude (Anthropic)". Is there any reason to believe this is not AI hallucinations? [1] https://stateofutopia.com/papers/2/intermediate-report.pdf

[flagged]

> Great question, and you're right to be skeptical.

Hi Claude! You're absolutely right!

Re: We broke 92% of SHA-256 – you should start to migrate from it

#60

I know people (especially around here) hate it when people just post AI output, and I generally agree, since it is trivial for anyone else who is interested to do the same thing. However, the majority of the comments here are from people seemingly asking the author (or someone else) to explain how significant this is, without having taken that step themselves. So while I normally wouldn't do this, in this case it see…

Claude didn't "think" anything
Post reply on HN