Live data from Hacker News

The first chosen-prefix collision for SHA-1

sha-mbles.github.io

71–80 of 369 posts

Re: The first chosen-prefix collision for SHA-1

#71

Earlier quoted context omitted.

SHA-256 and SHA-512 are both in the same family (SHA-2). Latacora says to use SHA-2. If you can get away with it, SHA-512/256 instead of SHA-256. But they're all SHA-2 family hash functions. https://latacora.micro.blog/2018/04/03/cryptographic-right-a... No need to bikeshed this. But if you must: SHA-512/256 > SHA-384 > SHA-512 = SHA-256 If you're wondering, "Why is SHA-384 better than SHA-512 and SHA-256?" the answe…

I'm super confused. Are SHA-256 and SHA256 different , and if so, why in the world would this be considered a sane naming scheme? If not, I completely do not understand the inequation you wrote, which seemingly lists SHA-256 (and -512) multiple times.

You're probably confused by "SHA-512/256", which does not mean SHA-512 or 256, but rather a truncated version of SHA-512: https://en.wikipedia.org/wiki/SHA-2 in the third paragraph.

Re: The first chosen-prefix collision for SHA-1

#72

> We note that classical collisions and chosen-prefix collisions do not threaten all usages of SHA-1. In particular, HMAC-SHA-1 seems relatively safe, and preimage resistance (aka ability to invert the hash function) of SHA-1 remains unbroken as of today. Nice to see this bit of intellectual honesty. Would be even nicer if they had explained what that means in terms of PGP keys.

It means if someone you want to impersonate uses the Web Of Trust, i.e. their key is signed by other people whose keys have been signed the same way, you can generate a GPG key for which all of these signatures are still valid. For example, if an attacker gains access to a victim email account, they could send to their contacts a "trusted" key (as explained above) and then use it to send signed documents to the victi…

> It means if someone you want to impersonate uses the Web Of Trust, i.e. their key is signed by other people whose keys have been signed the same way, you can generate a GPG key for which all of these signatures are still valid.

No...

> For example, if an attacker gains access to a victim email account, they could send to their contacts a "trusted" key (as explained above) and then use it to send signed documents to the victim's contacts.

Ok... But in this scenario the attacker has the victim’s new private key, so they don’t need to create a collision (using OP). They can just use the new private key to sign the documents. Right?

Re: The first chosen-prefix collision for SHA-1

#73

Earlier quoted context omitted.

SHA-256 and SHA-512 are both in the same family (SHA-2). Latacora says to use SHA-2. If you can get away with it, SHA-512/256 instead of SHA-256. But they're all SHA-2 family hash functions. https://latacora.micro.blog/2018/04/03/cryptographic-right-a... No need to bikeshed this. But if you must: SHA-512/256 > SHA-384 > SHA-512 = SHA-256 If you're wondering, "Why is SHA-384 better than SHA-512 and SHA-256?" the answe…

I'm super confused. Are SHA-256 and SHA256 different , and if so, why in the world would this be considered a sane naming scheme? If not, I completely do not understand the inequation you wrote, which seemingly lists SHA-256 (and -512) multiple times.

SHA-512/256 is a truncated SHA-512 that's shortened to 256 bits, it's a separate standard.

Re: The first chosen-prefix collision for SHA-1

#74

Earlier quoted context omitted.

SHA-256 and SHA-512 are both in the same family (SHA-2). Latacora says to use SHA-2. If you can get away with it, SHA-512/256 instead of SHA-256. But they're all SHA-2 family hash functions. https://latacora.micro.blog/2018/04/03/cryptographic-right-a... No need to bikeshed this. But if you must: SHA-512/256 > SHA-384 > SHA-512 = SHA-256 If you're wondering, "Why is SHA-384 better than SHA-512 and SHA-256?" the answe…

I'm super confused. Are SHA-256 and SHA256 different , and if so, why in the world would this be considered a sane naming scheme? If not, I completely do not understand the inequation you wrote, which seemingly lists SHA-256 (and -512) multiple times.

[deleted]

Re: The first chosen-prefix collision for SHA-1

#75

Earlier quoted context omitted.

Further details as to why Torvalds is not concerned: From the email... "I haven't seen the attack yet, but git doesn't actually just hash the data, it does prepend a type/length field to it. That usually tends to make collision attacks much harder, because you either have to make the resulting size the same too, or you have to be able to also edit the size field in the header." [...] "I haven't seen the attack detail…

What if somebody makes an attack where they can choose the size and then find a collision?

Like the two files on the linked page?

Re: The first chosen-prefix collision for SHA-1

#76
This kind of thing always brings me down a bit. It's not rational, but it does.

I mean I truly admire these folks skills, the math involved is obviously remarkable.

But I think the feeling is related to not being able to rely on anything in our field. Hard to justify going to the trouble of encrypting your backup. 10 years from now, it might be as good as plain text.

It's not security only, nothing seems to work in the long term. Imagine an engineer receiving a call at midnight about his bridge because gravity changed during daylight saving in a leap year. That's our field.

Re: The first chosen-prefix collision for SHA-1

#77

Earlier quoted context omitted.

It means if someone you want to impersonate uses the Web Of Trust, i.e. their key is signed by other people whose keys have been signed the same way, you can generate a GPG key for which all of these signatures are still valid. For example, if an attacker gains access to a victim email account, they could send to their contacts a "trusted" key (as explained above) and then use it to send signed documents to the victi…

> It means if someone you want to impersonate uses the Web Of Trust, i.e. their key is signed by other people whose keys have been signed the same way, you can generate a GPG key for which all of these signatures are still valid. No... > For example, if an attacker gains access to a victim email account, they could send to their contacts a "trusted" key (as explained above) and then use it to send signed documents to…

> No...

Why ?

> in this scenario the attacker has the victim’s new private key

You don't want to keep your private key in cleartext on your email provider servers, do you ?

Re: The first chosen-prefix collision for SHA-1

#78

Earlier quoted context omitted.

It's a lot of money for an academic researcher.

Is it? Multi-million grants are common in academia. A lot of research is expensive. When I worked in a lab the materials alone for a single day's experiment would frequently run into the thousands. E.g. the total human RNA samples we used cost many thousands of dollars per milligram . Admittedly this is a different field, but it's still academia.

> Multi-million grants are common in academia.

Not in the way you explain. Multi-million dollar grants are usually awarded over multiple years, and pay for multiple researchers’ salaries, as well as other resources, some of which are expected to outlast the project (e.g. microscopes, or hardware for databases). Burning 75k on a single experiment (which is effectively what was done here) is rare.

Note that this is true even for current hot topics such as biomedical (e.g. cancer) research, for which vast chunks of the federal budget have been allocated in multiple countries. Obtaining similar sums in less sexy fields is much harder. And even in biomedical research, multi-million dollar grants are considered large. Most grants are much smaller, they just don’t get talked about as much.

Since you mention human RNA samples I assume you know this. You mention the per-milligram cost but this is pretty misleading if you mean to imply that “milligram” is somehow little, because it isn’t: yes, the samples are tiny (≤1 µg of RNA is more typical than milligrams!), but so what? It’s not like we need more.

Re: The first chosen-prefix collision for SHA-1

#79

This kind of thing always brings me down a bit. It's not rational, but it does. I mean I truly admire these folks skills, the math involved is obviously remarkable. But I think the feeling is related to not being able to rely on anything in our field. Hard to justify going to the trouble of encrypting your backup. 10 years from now, it might be as good as plain text. It's not security only, nothing seems to work in t…

[deleted]

Re: The first chosen-prefix collision for SHA-1

#80

This kind of thing always brings me down a bit. It's not rational, but it does. I mean I truly admire these folks skills, the math involved is obviously remarkable. But I think the feeling is related to not being able to rely on anything in our field. Hard to justify going to the trouble of encrypting your backup. 10 years from now, it might be as good as plain text. It's not security only, nothing seems to work in t…

>> "Hard to justify going to the trouble of encrypting your backup."

Huh? If you're "encrypting" using SHA, I've got some bad news about those backups of yours.

Post reply on HN