[p2p-hackers] SHA1 broken?

Zooko O'Whielacronx zooko at zooko.com
Thu Feb 17 20:39:27 UTC 2005


following-up to my own post to correct and add URLs

I wrote:

> This topic -- whether collision-resistance is or is not necessary for 
> secure identification of content -- has been discussed extensively on 
> the cryptography at metzdowd mailing list recently.  Ben Laurie started 
> it with a post entitled "The pointlessness of MD5 attacks".  Here is 
> my contribution to that discussion:
>
> http://thread.gmane.org/gmane.comp.encryption.general/5717

^-- actually, that's the URL to Ben Laurie's original post that started 
the discussion.

Here's the URL I intended to give -- the URL to my own post about Alice 
the user, Bob the software maintainer, and Charles the Malicious 
Multimedia Master:

http://article.gmane.org/gmane.comp.encryption.general/5789

Here's the URL to Adam Back's post which suggested the technique which 
could lead to this bad situation without violating the 
second-preimage-resistance of the hash function:

http://article.gmane.org/gmane.comp.encryption.general/5729

Regards,

Zooko




More information about the P2p-hackers mailing list