5 ms·
> size, name I don't see why it would be necessary to provide a name and a size. If the hash is the same, we can be pretty sure that's the same file.
by sidarape 11y ago
> size, name
I don't see why it would be necessary to provide a name and a size. If the hash is the same, we can be pretty sure that's the same file.
- deleted 11y ago[deleted]
- lcswi 11y agoAn additional layer of security does not hurt. Forging a hash.collision at the exact same filesize is harder than an arbitrary size.
- emn13 11y agoThat's not really true. In fact, practical collision attacks vs. MD5 preserved the size - which if you think about it, makes sense. Unless a has function is utterly terrible, it's not unreasonable to assume it's easier to find a few correlated bits than it is to append bits. After all, to append bits you're going to need to somehow ensure that the internal fixed-size state of the hash algorithm cascades into the same state or nevertheless gives the same output, and since it's trivial to have a very, very high period state machine, that may mean appending huge numbers of bits. If safety were an argument you'd add an extra, unrelated hash function. E.g. even md5 is likely much harder to break if you also have the CRC32, even though CRC is a thoroughly insecure hash (and of course, you wouldn't use an insecure hash, now would you?)
- lcswi 11y agoThank you!
- dspillett 11y agoIt would not be necessary at all technically, but some people might be more reassured by the extra check.
- dspillett 11y agoYou are right that it would not be necessary at all technically, but some people might be more reassured by the extra check.
- Someone1234 11y agoI'm indifferent about name, but size has been shown to provide additional security. Generating two files where their hashes collide is extremely difficult. Generating two files where their hashes collide at the same size is near impossible, even after you break the hash function itself (e.g. with MD5 it requires much more compute power to generate two files with matching hashes and sizes than just hashes alone, since you're effectively looking for a subset of all collisions).
- sbierwagen 11y agoI feel like you're just effectively adding more bits to the hash length by appending the resource size; bits that might be better used by just adding more length to the hash.
- AgentME 11y agoAll MD5 hash collisions I've seen have been the same length: http://stackoverflow.com/questions/1224113/examples-of-hash-collisions http://stackoverflow.com/questions/1224113/examples-of-hash-.... I assume the common algorithm for making MD5 collisions requires you to start with a single value and mutate it in specific ways, while keeping the same length.