Forums: Sha-1 Broken. - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Sha-1 Broken. For real.

#1 User is offline   Tyrano 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 296
  • Joined: 13-February 04

Posted 16 February 2005 - 11:12 PM

From: http://www.schneier....ha1_broken.html

Quote

SHA-1 has been broken. Not a reduced-round version. Not a simplified version. The real thing.

The research team of Xiaoyun Wang, Yiqun Lisa Yin, and Hongbo Yu (mostly from Shandong University in China) have been quietly circulating a paper describing their results:

    * collisions in the the full SHA-1 in 2**69 hash operations, much less than the brute-force attack of 2**80 operations based on the hash length.

    * collisions in SHA-0 in 2**39 operations.

    * collisions in 58-round SHA-1 in 2**33 operations.

This attack builds on previous attacks on SHA-0 and SHA-1, and is a major, major cryptanalytic result. It pretty much puts a bullet into SHA-1 as a hash function for digital signatures (although it doesn't affect applications such as HMAC where collisions aren't important).

The paper isn't generally available yet. At this point I can't tell if the attack is real, but the paper looks good and this is a reputable research team.

More details when I have them.

0

#2 User is offline   belgther 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 650
  • Joined: 06-October 04

Posted 18 February 2005 - 05:55 AM

i saw it somewhere else...
but i don't know where, maybe here, i heard that it's been kept quite secret how it's been done...
"The wisest one is the one who knows himself/herself." Quote of the life
belgther... aka... belgther
0

#3 User is offline   archphase 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 20
  • Joined: 15-September 04

Posted 18 February 2005 - 02:17 PM

belgther, on Feb 18 2005, 01:55 PM, said:

i saw it somewhere else...
but i don't know where, maybe here, i heard that it's been kept quite secret how it's been done...


SHA0 was taken off the market in '93? because NSA found some clearly undisclosed vulnerbilty, some french researches in '95 announced their attack but it was never confirmed as the attack.

Anyways, what a parody upon it's acronym.
0

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting