Live data from Hacker News

Browser-Wars History: MD5-Hashed Posts Declassified

robert.ocallahan.org

31–40 of 75 posts

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#31

Earlier quoted context omitted.

Maybe use SHA256 rather than MD5. A few years hence ease of producing MD5 collisions might render moot anything that you had to say.

I don't think that's necessary. This isn't really a cryptographic use of the hash. Between the legitimate text of the blog entry and whatever arbitrary (likely nonsensical) string produces an MD5 collision, it's going to be pretty obvious which is which.

Isn't it feasible to construct two sets of legible texts with the same MD5 hash now?

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#32
post #14

I expected an article about 1990s browser wars. 2007-2008 is not ancient in my book.

10 years is a long time. This was back when I still heard people seriously asking if the internet would last. It was even plausible! Google was only a few years out from its IPO. Few people thought the internet could help elect a president (and I don't mean the current guy). A lot changed in the last ten years. It may not seem like it because most of those changes were refinements on things we already had at the time…

"people seriously asking if the internet would last"

I guess I can see this seeming reasonable in the early 1940s, but it was fully crazy even before Tim built this awful Heath Robinson hypertext system we're using, let alone this century. The Network is not like cars, or pants, it's not a passing fad that societies grow bored of, it's at the heart of what we are as people, it will outlive us all.

I remember trying to explain a lot of this stuff in the early 1990s when I was a teenager - to my parents and being bewildered by how little they understood what had already happened and what would inevitably happen next. It was really like I'm stood on a beach, there has been a distant rumble and the tide is going out very fast, and I'm saying "Inland. Mum, Dad, right now. Don't stop to pick up towels and stare at the horizon, we must hurry inland or we will drown" and they don't get it at all.

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#33
post #31

Earlier quoted context omitted.

I don't think that's necessary. This isn't really a cryptographic use of the hash. Between the legitimate text of the blog entry and whatever arbitrary (likely nonsensical) string produces an MD5 collision, it's going to be pretty obvious which is which.

Isn't it feasible to construct two sets of legible texts with the same MD5 hash now?

Sort of, in PDF form, by inserting invisible images/data crafted to create the collision.

I haven't seen a collision demonstration with plain text that could be a practical attack.

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#34
post #31

Earlier quoted context omitted.

I don't think that's necessary. This isn't really a cryptographic use of the hash. Between the legitimate text of the blog entry and whatever arbitrary (likely nonsensical) string produces an MD5 collision, it's going to be pretty obvious which is which.

Isn't it feasible to construct two sets of legible texts with the same MD5 hash now?

Legible, maybe, but I don't think you'll be able to collide the hash with natural language, so you will need an excuse as to why the revealed text has weird nonsense in it that is actually there to collide the hash.

You can also "see" this, once you suspect it's going on, if you're a cryptanalyst and have the tools to see inside the hash, you can see basically such collisions involving getting the internal state into an awkward place, and then forcing it from there where they want to go, that could happen by accident, but only by truly astronomical bad luck, so it's a pretty good smoking gun.

MD5 is a bad idea for situations where a machine will be verifying, because machines aren't good at saying "that's odd...", enhancing them to do so is _way_ more effort than just using SHA-256 instead. But for something like this where a human will be examining things by hand, it's fine.

For SHA-1 (which we knew at the time would be broken shortly, and then in practice it was less than a year before Google and some academics announced their full collision) we reviewed special "Exception" SHA-1 SSL issuances by hand on m.d.s.policy after the official deadline for SHA-1 issuance and I asked for one application to be explained or rejected on the basis that the requested certificate had bizarre short gibberish values for "Organizational Unit". The applicant provided an explanation (which was maybe plausible but not up to the standard of transparency needed in the circumstances) but agreed to accept certificates missing the OU value altogether instead. That's the sort of thing you'd catch if a human examines what was hashed rather than a machine. I had no reason to believe that applicant was trying anything sinister, but the point of the manual examinations was to ensure everybody can see there were no shenanigans going on (and to make it a complete pain -- if the process was easy it would have become routine and defeated the purpose of prohibiting new SHA-1 issuance, being annoying was a feature).

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#35
post #14

I expected an article about 1990s browser wars. 2007-2008 is not ancient in my book.

10 years is a long time. This was back when I still heard people seriously asking if the internet would last. It was even plausible! Google was only a few years out from its IPO. Few people thought the internet could help elect a president (and I don't mean the current guy). A lot changed in the last ten years. It may not seem like it because most of those changes were refinements on things we already had at the time…

Wow. You just made me realize that most of the big changes I'd mentally spread out over 20 or 25 years happened just in the last decade. In 2007, I was considered a pretty high-tech guy for just having a blog and being able to edit it. It was still possible to add entries to Wikipedia about things that were not super obscure or recent news. phpBB forums still ruled the Internet. And reddit was a toddler!

It has been like that C. S. Lewis quote - day by day, it felt like nothing big has changed, but looking back, everything is different.

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#36
post #23
post #9

Opera made the bet he proposed and lead themselves down a path to irrelevance.

As one of the few who paid for a web browser (paid $29 for Opera 7 in 2003), it looked to me like Opera really had no choice. There was a post from an Opera insider that I can't find but it was basically this: the web's complexity was evolving faster than the Opera team could maintain their proprietary Presto rendering engine. Switching away from Presto and building on WebKit was a basic matter of survival. Yes, they…

(I worked at Opera during the WebKit/Chromium transition and work at Mozilla now. But in both cases I'm just a normal individal-contributor type employee with no special insight into strategy or decision making).

There are always options. Opera could have doubled-down on Presto; putting more people on the core team, and focussing efforts to keep up with, and surpass, WebKit/Gecko. After all, that's basically the option that Mozilla took, which has resulted in Firefox Quantum. Would that have worked? It's hard to say. I would guess not, but I'm not sure the alternative really did either. Maybe Opera was already too far down the web-compat death spiral to engineer a way out. I don't know of a long-term bet like Rust that could have come good at the right time.

Certainly the top-level culture of the organisations was different; Opera's leadership were very concerned with maintaining/maximising the value of their shares, whereas Mozilla is more clearly driven by ideological goals around the success of the open web. Opera also had a (historically well justified) belief that they could do more with fewer engineers than other compaines. That seemed to work up to a point, but once the difference in resources became too great it was hard to change the approach.

Certainly one lesson is that it's hard, maybe impossible, to be a niche browser with a unique rendering engine. That is arguably a failing of the web, but nevertheless it's a strong indication that arguments that e.g. Mozilla should aim Firefox at small ideologically-driven markets are dangerous. One interpretation of the Opera history is that they were too focussed for too long on the subset of users who wanted a browser with lots of features and configuration possibilities. A product that suits those people might be actively offputting to other users, so inhibiting marketshare growth when faced with competition targetting simplicity and sane defaults.

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#37
Somehow, everybody pretends as if Webkit is some proprietary, closed source rendering engine, but after all, it is the great success of the KDE/Konqueror rendering engine, being adopted by some huge corporations (Apple, Google). [1]

While I appreciate that we still have the independent Firefox and its brand new Quantum engine, sometimes I feel like the Konqueror/KHTML team does not receive the appropriate tribute for laying the foundation for the dominant KHTML/Webkit/Blink engine.

[1] https://en.wikipedia.org/wiki/WebKit#Origins

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#38
post #36
post #23

Earlier quoted context omitted.

As one of the few who paid for a web browser (paid $29 for Opera 7 in 2003), it looked to me like Opera really had no choice. There was a post from an Opera insider that I can't find but it was basically this: the web's complexity was evolving faster than the Opera team could maintain their proprietary Presto rendering engine. Switching away from Presto and building on WebKit was a basic matter of survival. Yes, they…

(I worked at Opera during the WebKit/Chromium transition and work at Mozilla now. But in both cases I'm just a normal individal-contributor type employee with no special insight into strategy or decision making). There are always options. Opera could have doubled-down on Presto; putting more people on the core team, and focussing efforts to keep up with, and surpass, WebKit/Gecko. After all, that's basically the opti…

> which has resulted in Firefox Quantum.

How is Quantum doing? On my computer, it's a lot slower; there are slow spinners in the tab titles and another kind of spinner for loading pages that often keeps me from seeing pages even after I already loaded them.

Re: Browser-Wars History: MD5-Hashed Posts Declassified

#40
post #14

I expected an article about 1990s browser wars. 2007-2008 is not ancient in my book.

10 years is a long time. This was back when I still heard people seriously asking if the internet would last. It was even plausible! Google was only a few years out from its IPO. Few people thought the internet could help elect a president (and I don't mean the current guy). A lot changed in the last ten years. It may not seem like it because most of those changes were refinements on things we already had at the time…

Ten years ago my home page showed up on the first page (top ten) of search results for a Google search for just my first name, or just my last name. I've never been particular famous—there were just no individuals with a web presence, outside of tech.

[But mostly I just came here to practice using an em dash correctly…]

Post reply on HN