Leveraging synergy in this championship year
Michael Davies
Local
News
Software
Utility
Powered by PyBlosxom
Copyright © 2003, 2004, 2005, 2006, 2007, 2008 Michael Davies, |
SHA-1 partial chosen plaintext attacks successfulSo back in February, we found out that SHA-1 was gone - researchers could generate 2 plaintexts that generated the same hash. But at least the plaintexts were gibberish, meaning that while SHA-1 was broken, the break was of limited use. Now comes a more serious blow - in a similar vein to the previously reported MD5 attacks it's now possible to choose part of the plaintext and still get the same hash. Yikes. Quoting the article:
Using the new method, it is possible, for example, to produce two HTML
documents with a long nonsense part after the closing |