4 ms·
That doesn't appear to be true. From http://www.mscs.dal.ca/~selinger/md5collision/ http://www.mscs.dal.ca/~selinger/md5collision/: It is now well-known that t
by doty 16y ago
That doesn't appear to be true. From http://www.mscs.dal.ca/~selinger/md5collision/ http://www.mscs.dal.ca/~selinger/md5collision/:
It is now well-known that the crytographic hash function MD5 has been broken. [...] The following is an improvement of Diaz's example, which does not need a special extractor. Here are two pairs of executable programs (one pair runs on Windows, one pair on Linux) [...] Here, you can download the software that I used to create MD5-colliding executable files.
- tumult 16y agoThe person doing the spoofing has to create both of the files. You can't take an existing file created by a third party, and then generate a collision against it (yet).
- jozwiakjohn 16y agoSure you can, if you have arbitrarily long but still finite time. (Think recursive versus recursively enumerable sets.)
- lambda 16y agoWhen he says "can't", he doesn't mean it's impossible, he means it's infeasible. There are no techniques for doing it fast enough that anyone has to worry about it being done.