Live data from Hacker News

Sha256 vulnerability for full rounds

github.com

11–12 of 12 posts

Re: Sha256 vulnerability for full rounds

#11
post #8
post #3

Same thing that's explained by https://crypto.stackexchange.com/a/48586 ? TLDR: It's easy to find fixed points of hashes like SHA-256.

laie makes it sound like they found two things (free-start collision attack and circular hash attack). I agree the free-start part isn't very interesting but I don't think we have enough information to confirm or dismiss whether the circular hash attack part is novel.

Using that philosophy, we have to be cautious about whether or not the Riemann hypothesis has been solved every time someone uploads a paper claiming a proof to arXiv, even if it's nonsensical (which this "proof" is), just because we haven't had a team of mathematicians peer review it.

Let me assure you: there is nothing novel here. There is no vulnerability. You want to start from a place of skepticism with these things, not a place of, "Well we don't have enough information to say it's not true..."

Re: Sha256 vulnerability for full rounds

#12
post #10
post #8

Earlier quoted context omitted.

laie makes it sound like they found two things (free-start collision attack and circular hash attack). I agree the free-start part isn't very interesting but I don't think we have enough information to confirm or dismiss whether the circular hash attack part is novel.

Could you unpack "circular hash attack"? Googling was not very helpful.

"circular hash attack" left me confused and waiting to hear the full story. I totally agree with "Extraordinary claims require extraordinary evidence".
Post reply on HN