3 ms·
Is the very accessible 120K$ estimate just for an arbitrary collision, or is it also possible to cheaply obtain a collision with chosen start or end, or a preim
by devit 11y ago
Is the very accessible 120K$ estimate just for an arbitrary collision, or is it also possible to cheaply obtain a collision with chosen start or end, or a preimage, or a preimage with chosen start or end?
- coldpie 11y agoI have only a little crypto experience (uni courses and as a light hobby), so I could be wrong. My understanding is that a "collision attack" is a well-defined term, where the attacker chooses both preimages. An attack where you are given a preimage and a hash and must compute a second preimage with the same hash is called a "second preimage" attack. A "first preimage" attack would be finding a message that computes to a given hash. There are different attack scenarios for each attack type, one isn't strictly a subset of another. The paper given here describes a collision attack, so they chose both messages that result in the same hash. Further, they also generated different IV values for each SHA1 algorithm, while in practice the IV value is fixed. This is what "freestart" means. I found this useful reference: http://cstheory.stackexchange.com/questions/585/what-is-the-difference-between-a-second-preimage-attack-and-a-collision-attack http://cstheory.stackexchange.com/questions/585/what-is-the-... I hope this answers your question.