Live data from Hacker News

The first chosen-prefix collision for SHA-1

sha-mbles.github.io

191–200 of 369 posts

Re: The first chosen-prefix collision for SHA-1

#191
post #127

Earlier quoted context omitted.

If the data is shorter than the hash shouldn't it be the same data I backed up with reasonably high probability?

No. http://matt.might.net/articles/counting-hash-collisions/

That doesn't apply here, since the birthday paradox is about the existence of a collision, not that any particular sequence collides.

Most people in the room will still have unique birthdays even if one pair share theirs.

Re: The first chosen-prefix collision for SHA-1

#192

This kind of thing always brings me down a bit. It's not rational, but it does. I mean I truly admire these folks skills, the math involved is obviously remarkable. But I think the feeling is related to not being able to rely on anything in our field. Hard to justify going to the trouble of encrypting your backup. 10 years from now, it might be as good as plain text. It's not security only, nothing seems to work in t…

There's an MC Frontalot song called "Secrets from the Future" and the refrain is "You can't hide secrets from the future." It's something of a useful mantra to remind oneself that if "the future" is a part of your threat model, yes your encryption likely isn't enough because on a long enough timescale it is likely "the future" will crack it. As with any other security issue, the question is "what is your threat model…

This biblical prophecy from Luke 12,3 is solo true: " What you have said in the dark will be heard in the daylight, and what you have whispered in the ear in the inner rooms will be proclaimed from the roofs."

Re: The first chosen-prefix collision for SHA-1

#193

Earlier quoted context omitted.

Are there materials that show a ten year head start?

For an early example, differential cryptanalysis methods were 'discovered' in late 1980s by Biham and Shamir; but it later turned out that resistance to it was pushed as a design consideration already back in 1974 when DES was designed, so NSA knew of it at least then, that's more than a decade. We know that British intelligence (who don't have as much resources as NSA) had developed the RSA equivalent something like…

This is fascinating; are there any readings/sources for similar events, i.e. governments "predicting" academia?

I am aware of the 2015 plan to "transition soon(tm)", but that's because I was alive 5 years ago. Other earlier events would be super cool to read up on.

Re: The first chosen-prefix collision for SHA-1

#194

Earlier quoted context omitted.

For an early example, differential cryptanalysis methods were 'discovered' in late 1980s by Biham and Shamir; but it later turned out that resistance to it was pushed as a design consideration already back in 1974 when DES was designed, so NSA knew of it at least then, that's more than a decade. We know that British intelligence (who don't have as much resources as NSA) had developed the RSA equivalent something like…

How many mathematicians are working for NSA? How many public research cryptographers are there?

One thing is that proper public cryptographers are very rare, there's a handful of effective teams - e.g. MIT has Rivest and associates, there are a bunch of other places, but most universities, including quite serious ones, don't have anyone doing reasonable cryptographic research. Cryptocurrencies caused a recent boom, but it's a niche with separate, specific goals that doesn't advance the rest of the field much.

It's hard to give good numbers, we'd have to look at Snowden leaks and others, but I haven't done much about that. Here's an earlier HN comment https://news.ycombinator.com/item?id=6338094 that estimates 600 proper mathemathic researchers working on crypto, and it seems quite plausible to me that it would be more research power than the entire public academia - especially because in many countries who do take this field seriously (e.g. China, Russia, Iran) there's no real public research in crypto happening because that's classified by default. I mean, prety much all academic research happens through targeted grants by governments, and who other than deparment of defence (or similar organizations in other countries) would be funding cryptographic research?

Also, I'll quote Bruce Shneier (2013, https://www.schneier.com/essays/archives/2013/09/how_advance...) regarding their budget - "According to the black budget summary, 35,000 people and $11 billion annually are part of the Department of Defense-wide Consolidated Cryptologic Program. Of that, 4 percent—or $440 million—goes to 'Research and Technology.' That's an enormous amount of money; probably more than everyone else on the planet spends on cryptography research put together."

Re: The first chosen-prefix collision for SHA-1

#195

Earlier quoted context omitted.

What if somebody makes an attack where they can choose the size and then find a collision?

Like the two files on the linked page?

The two files on the linked page were both full of junk data. I suspect that those files being of the same length isn't the norm.

Re: The first chosen-prefix collision for SHA-1

#196

> By renting a GPU cluster online, the entire chosen-prefix collision attack on SHA-1 costed us about 75k USD. So they just decided to try their attack and spend two years worth of salary on it?? That's crazy.

As GPU's get better the cost will come down. Was it a massive cluster of RTX2060's or something?

Re: The first chosen-prefix collision for SHA-1

#197
post #179

This kind of thing always brings me down a bit. It's not rational, but it does. I mean I truly admire these folks skills, the math involved is obviously remarkable. But I think the feeling is related to not being able to rely on anything in our field. Hard to justify going to the trouble of encrypting your backup. 10 years from now, it might be as good as plain text. It's not security only, nothing seems to work in t…

No, the bridge collapsed because it was never touched again after initial deployment, for 10 years. How are buildings doing in Chernobyl? Don’t neglect your data, if you want to keep it safe always. :P

Dude, Chernobyl reactor by design was nuclear bomb.

P.S. My father (still alive) was one of thousands of common liquidators of Chernobyl disaster from May to July 1986. Many of his coworkers, that lived with him in same tent, already dead.

Re: The first chosen-prefix collision for SHA-1

#198

This kind of thing always brings me down a bit. It's not rational, but it does. I mean I truly admire these folks skills, the math involved is obviously remarkable. But I think the feeling is related to not being able to rely on anything in our field. Hard to justify going to the trouble of encrypting your backup. 10 years from now, it might be as good as plain text. It's not security only, nothing seems to work in t…

> Hard to justify going to the trouble of encrypting your backup. 10 years from now, it might be as good as plain text.

When has that happened? Public key cryptography and symmetric key cryptography are still doing fine as far as I'm aware, and the latter doesn't even seem to be vulnerable to quantum computing.

Moreover, SHA-1 has been considered insecure for, what, at least 10 years? The fact that a cryptographic hash function has been widely considered insecure and widely recommended for deprecation a decade before a proof of concept even emerges is, to me, something to feel very good about.

Re: The first chosen-prefix collision for SHA-1

#199

Earlier quoted context omitted.

You're probably confused by "SHA-512/256", which does not mean SHA-512 or 256, but rather a truncated version of SHA-512: https://en.wikipedia.org/wiki/SHA-2 in the third paragraph.

So why would a truncated version of SHA-512 be better than SHA-512? And why is SHA-512 = SHA-256?

[deleted]

Re: The first chosen-prefix collision for SHA-1

#200
post #157

Earlier quoted context omitted.

SHA1 isn't broken for hashes.

SHA1 is vulnerable to preimage attacks in reduced round variants. The findings keep steadily improving. https://en.wikipedia.org/wiki/Preimage_attack This means if a storage system just uses SHA1 to detect duplication, you can abuse the ability to create a collision to possibly do bad things to the storage system.

>SHA1 is vulnerable to preimage attacks.

From your linked article:

>All currently known practical or almost-practical attacks on MD5 and SHA-1 are collision attacks. In general, a collision attack is easier to mount than a preimage attack, as it is not restricted by any set value (any two values can be used to collide).

Post reply on HN