3 ms·
Is a 30 day disclosure period really enough for something like this? It's obviously not possible to 'fix' big systems that rely on SHA-1 such as git or github i
by RyanZAG 10y ago
Is a 30 day disclosure period really enough for something like this? It's obviously not possible to 'fix' big systems that rely on SHA-1 such as git or github in only 30 days. Hardware devices that use SHA-1 as a base for authenticating firmware updates?
- gcp 10y agoSHA1 was shown to be flawed in 2005. That's more than 30 days ago.
- hvidgaard 10y agoSaying it was shown to be flawed is being nice. It was outright broken 12 years ago as it was shown that you could find collisions with far less complexity that a bruteforce attack. What has happened is that someone created the code to actually carry out an attack, and showed that it will cost around $110K today.
- prefect42 10y agoRight, the Wikipedia page for SHA1 does show research on a variety of possible attacks, starting from 2005.
- anilgulecha 10y agoThe article states 90 days. > we will wait 90 days before releasing code that allows anyone to create a pair of PDFs that hash to the same SHA-1 sum given two distinct images with some pre-conditions
- djaychela 10y agoI may have misread, but I thought from the article they said that the period would be 90 days before the release?
- RubyPinch 10y agogit does some other funky things, usually it just uses the pre-existing object, or crashing http://stackoverflow.com/a/9392525 http://stackoverflow.com/a/9392525 It might change, but the response could quite likely be a stubborn "I said no before, so I'll say no now" - - - This attack has been known since 2013, that is a really long disclosure time (the main thing today is proving that the attack isn't theoretical)