Elwing’s Weblog
Elwing’s rantings and ravings
  • About Me
  • S/MIME Plugin
  • What I'm Doing...

    • Getting ready to head overseas again 11 hrs ago
    • waiting to be let back into WoW - queue started at 277, down to 92. Brian is going to play with me later! (different server) 2 days ago
    • inanimate things that look like they're breathing is my particular hallucination from the chloroquine - kinda interesting 3 days ago
    • More updates...

    Powered by Twitter Tools.

  • Past Posts

    February 2005
    S M T W T F S
    « Jan   Mar »
     12345
    6789101112
    13141516171819
    20212223242526
    2728  
SHA-1 “Broken”
Author: elwing
• Wednesday, February 16th, 2005

From Bruce Schneier’s weblog: SHA-1 Broken. The same researchers that brought you a broken SHA-0, have now brought you a broken SHA-1. Xiaoyun Wang, Yiqun Lisa Yin, and Hongbo Yu have “broken” SHA-1 proving that collisions do exist, and that they’re relatively easy to find - relatively is a big stretch there.

I’m enough of a cryptogeek to understand some of it, but not all of it, so I’ll be waiting for the people who know better to give layman’s details, but it means a big problem with digital signatures. Granted, this technique may not allow someone to change “attack at dawn” to “attack at dusk” in any meaningful way, but what about SSL where you “sign” a random challenge?

Category: Technology
You can follow any responses to this entry through the RSS 2.0 feed. Both comments and pings are currently closed.

Possibly Related

  • SHA-0 broken and SHA-1 weakened
  • Firewall woes
  • Fifty Fifty Book Challenge

One Response

  1. 1
    Brian DeRocher 
    Wednesday, 16. February 2005

    Even if Eve can create a response to a challenge and fake your digital signature, it’s very unlikely that she will create the correct response.

« Microsoft CA and Thunderbird
Wordpress 1.5! »
Subscribe RSS © 2009 Elwing’s Weblog
Free Wordpress Theme by TemplateLite.com | Coded by Web Hosting Refer
This blog is protected by dr Dave's Spam Karma 2: 7337 Spams eaten and counting...