[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <011401c51541$fdafedb0$0400a8c0@p14n>
Date: Thu, 17 Feb 2005 14:42:40 -0800
From: <dullien@....de>
To: "Robert Sussland" <robert@...wood.org>,
"Gadi Evron" <gadi@...ila.gov.il>
Cc: <bugtraq@...urityfocus.com>
Subject: Re: SHA-1 broken
Hey all,
> We abandon the requirement of collision resistance. This is a strange
> requirement, and is not supported by experience. Collision resistance
we might think of changing the requirement of collision resistance
to "collision resistance in input data that is valid ASCII text". The
attacks on MD5 used the weak avalanche of the highest-order bit
in 32-bit words for producing the collision, basically precluding the
possibility of generating colliding ASCII text.
Cheers,
Thomas Dullien
Powered by blists - more mailing lists